Two iPhone Exploit Tools Once Owned by Governments Are Now in the Hands of Ordinary Criminals

Coruna and DarkSword, sophisticated iPhone attack kits that began as nation-state spy tools, are spreading fast. Security researchers have found roughly 17,000 websites hosting them, and criminals are already making them worse.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A darkened computer workspace with an iPhone displayed on a stand, sophisticated hacking tool interfaces visible on surrounding screens, subtle indicators of cr
Share

Key points

  • IVerify has tracked approximately 17,000 domains hosting updated versions of Coruna and DarkSword as of mid-2026.
  • DarkSword has been active since November 2025, targeting iPhones running iOS 18.4 through 18.7 across Malaysia, Saudi Arabia, Turkey and Ukraine.
  • Coruna deploys 23 separate software flaws across five attack chains and is estimated to have cost between $30 million and $40 million to build.
  • Apple has patched the flaws behind both tools, but millions of iPhones remain unpatched and exposed.
  • Researchers at Black Hat USA 2026 warned this is the first time nation-state-grade iPhone exploitation has spilled into organised crime at meaningful scale.

Two iPhone attack toolkits developed for government spy programmes have escaped into the wider criminal world, and researchers say the spread is accelerating.

The tools are called Coruna and DarkSword. Each is what researchers call an exploit chain: a sequence of software flaws that, when triggered one after another, gives an attacker full control of a phone. Think of it like a lockpick set that opens several doors in a row, ending with full access to everything inside.

How bad is this, really?

Bad enough that Matthias Frielingsdorf, vice president of research at the mobile security firm iVerify, told an audience at Black Hat USA 2026 last week that this is the first time he has seen tools of this quality move from government use into organised crime at scale. His firm has found roughly 17,000 websites built to deliver the attacks. We covered DarkSword's earlier appearance in a Chinese lookalike-site campaign on 3 August; what's new here is the sheer breadth of criminal adoption.

"In five minutes, you can deploy an iOS exploit chain," Frielingsdorf said. "This is extremely dangerous and extremely easy to proliferate."

IVerify researchers also spotted criminals mixing techniques from both toolkits to create hybrid versions they informally named "Darkuna," which include new ways to hide from security software and new methods to stay on a phone after a restart.

What do these tools actually do to your phone?

DarkSword steals, in Frielingsdorf's words, "basically everything." That means saved passwords stored in the iPhone's Keychain, Wi-Fi credentials, iCloud data, photos and cryptocurrency wallet credentials. It exploits six separate security flaws: memory corruption bugs CVE-2025-31277, CVE-2025-43529, CVE-2025-43510, CVE-2025-43520, an authentication bypass tracked as CVE-2026-20700, and an ANGLE graphics flaw tracked as CVE-2025-14174. Apple patched DarkSword in April 2026.

Coruna is older and more expensive. It targets iPhones running iOS 13 through iOS 17.2.1 and is believed to have cost $30 million to $40 million to build, originally commissioned by a government contractor. It spreads through watering-hole attacks, where victims visit a website rigged to attack their browser without any further action on their part. Once inside, it hides within legitimate system processes like the power daemon and location daemon, so it doesn't look like spy software. Apple patched the underlying flaws in 2023 and 2024.

Tool iOS versions targeted Known flaws used Apple patch date
DarkSword 18.4 to 18.7 6 CVEs April 2026
Coruna 13 to 17.2.1 23 CVEs 2023 to 2024

Should you update right now?

Yes. Both toolkits rely entirely on flaws Apple has already fixed. Go to Settings, then General, then Software Update. That one step closes the door on everything described here.

Be cautious about links arriving in text messages or emails you weren't expecting. Coruna is browser-delivered, so avoiding unfamiliar links directly reduces your exposure. Cryptocurrency holders are a stated target of DarkSword; moving large holdings to a hardware wallet not connected to the internet is worth the inconvenience.

The thing to watch: Frielingsdorf tied Coruna infrastructure to a Chinese organised crime group and DarkSword to multiple operators worldwide. These don't belong to a single government anymore, and criminal developers are actively improving them. Patch windows that used to matter in months now matter in days.

© 2026 Threat Vectr