Russian UNC6353 Uses Coruna and Darksword iOS Exploit Kits Across iOS 13–18.7 Targeting Financial Espionage and Data Theft
Summary
Hide ▲
Show ▼
Apple has expanded security updates for iOS 18.7.7 and iPadOS 18.7.7 to protect devices still running iOS 18 from the DarkSword exploit kit, without requiring full OS upgrades. This follows continued exploitation of DarkSword since July 2025 across multiple countries, with attacks leveraging six vulnerabilities to deploy data-stealing malware like GhostBlade, GhostKnife, and GhostSaber through watering hole attacks on compromised websites. The campaign remains linked to Russian threat actor UNC6353 and associated groups including UNC6748 and Turkish vendor PARS Defense, with Coruna and Darksword exploit kits now confirmed as closely related frameworks sharing origins in the 2019–2023 Operation Triangulation campaign. Coruna has evolved from a precision espionage tool into a mass-exploitation framework with 23 exploits across five chains, while Darksword targets iOS 18.4–18.7 and has been publicly leaked on GitHub. Apple has patched all exploited flaws in recent releases (18.7.3, 26.2, 26.3.1), and CISA has mandated federal agencies patch three DarkSword-linked vulnerabilities (CVE-2025-31277, CVE-2025-43510, CVE-2025-43520) by April 3, 2026. The commoditization of these iOS exploitation tools elevates risk to end-users globally.
Timeline
-
18.03.2026 16:02 7 articles · 15d ago
Darksword iOS Exploit Kit Discovered Targeting iOS 18.4–18.6.2
Apple expands security coverage by releasing iOS 18.7.7 and iPadOS 18.7.7 on April 1, 2026 to protect devices still running iOS 18 from DarkSword's six vulnerabilities without requiring full OS upgrades. The update covers iPhone XR through iPhone 16 models, iPhone SE (2nd and 3rd generation), multiple iPad mini, iPad Air and iPad Pro models, and iPad (7th generation). DarkSword exploitation has been active since July 2025 across multiple countries, using data-stealing malware including GhostBlade, GhostKnife, and GhostSaber in watering hole attacks on compromised websites. The public leak of DarkSword on GitHub increases the risk of commoditized exploitation beyond targeted campaigns, prompting Apple's unusual decision to backport patches to an older major OS version.
Show sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits — thehackernews.com — 27.03.2026 19:22
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
04.03.2026 15:28 9 articles · 29d ago
Coruna Exploit Kit Used in Multiple Campaigns by Various Threat Actors
Kaspersky GReAT confirms Coruna is a continuously maintained evolution of the Operation Triangulation framework, with code-level continuity in kernel exploits (CVE-2023-32434 and CVE-2023-38606) dating to 2019. The framework includes explicit checks for Apple's A17, M3, M3 Pro, and M3 Max chips and supports iOS versions below 14.0 beta 7, 14.7, 16.5 beta 4, 16.6 beta 5, and 17.2. Attacks begin via compromised Safari websites with a stager that fingerprints devices, selects RCE and PAC exploits, and retrieves encrypted metadata. Payloads are decrypted with ChaCha20, decompressed with LZMA, and parsed via custom container formats before executing appropriate kernel exploits, Mach-O loaders, and launchers. The payloads support ARM64 and ARM64E architectures. Originally a precision espionage tool, Coruna is now deployed indiscriminately in campaigns targeting cryptocurrency theft and broader data exfiltration.
Show sources
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 — thehackernews.com — 04.03.2026 15:28
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
Information Snippets
-
The Coruna exploit kit targets iOS versions 13.0 to 17.2.1 and includes five full exploit chains and 23 exploits.
First reported: 04.03.2026 15:283 sources, 9 articlesShow sources
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 — thehackernews.com — 04.03.2026 15:28
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits — thehackernews.com — 27.03.2026 19:22
-
The kit uses non-public exploitation techniques and mitigation bypasses.
First reported: 04.03.2026 15:283 sources, 8 articlesShow sources
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 — thehackernews.com — 04.03.2026 15:28
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
The exploit kit has been used by multiple threat actors, including government-backed groups and financially motivated actors.
First reported: 04.03.2026 15:283 sources, 7 articlesShow sources
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 — thehackernews.com — 04.03.2026 15:28
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
The kit was first observed in February 2025 and has since been linked to campaigns involving Russian and Chinese actors.
First reported: 04.03.2026 15:283 sources, 9 articlesShow sources
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 — thehackernews.com — 04.03.2026 15:28
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
The exploit kit leverages vulnerabilities in WebKit and other components, some of which were patched by Apple but remained undocumented until later.
First reported: 04.03.2026 15:283 sources, 8 articlesShow sources
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 — thehackernews.com — 04.03.2026 15:28
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
The kit is designed to fingerprint devices and deliver appropriate exploits based on the iOS version.
First reported: 04.03.2026 15:283 sources, 8 articlesShow sources
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 — thehackernews.com — 04.03.2026 15:28
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
The kit avoids execution on devices in Lockdown Mode or private browsing.
First reported: 04.03.2026 15:283 sources, 5 articlesShow sources
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 — thehackernews.com — 04.03.2026 15:28
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
-
The Coruna exploit kit marks a shift from targeted spyware attacks to broader exploitation of iOS devices.
First reported: 04.03.2026 15:282 sources, 6 articlesShow sources
- Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 — thehackernews.com — 04.03.2026 15:28
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
The Coruna exploit kit includes a stager loader called PlasmaGrid, which targets cryptocurrency wallet apps such as MetaMask, Phantom, Exodus, BitKeep, and Uniswap.
First reported: 04.03.2026 21:063 sources, 6 articlesShow sources
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The exploit kit was used in watering hole attacks targeting iPhone users visiting compromised Ukrainian websites in summer 2025.
First reported: 04.03.2026 21:063 sources, 5 articlesShow sources
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The exploit kit was also observed on fake Chinese gambling and crypto websites in late 2025, attributed to the financially motivated Chinese threat actor UNC6691.
First reported: 04.03.2026 21:063 sources, 6 articlesShow sources
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The exploit kit includes extensive documentation with docstrings and comments authored in native English.
First reported: 04.03.2026 21:063 sources, 4 articlesShow sources
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits — thehackernews.com — 27.03.2026 19:22
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
The exploit kit leverages vulnerabilities first identified during Operation Triangulation, which abused undocumented hardware features in Apple's devices.
First reported: 04.03.2026 21:062 sources, 4 articlesShow sources
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The exploit kit targets wallet recovery phrases (BIP39), sensitive text strings such as 'backup phrase' and 'bank account', and data stored in Apple Memos.
First reported: 04.03.2026 21:063 sources, 5 articlesShow sources
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The stolen data is encrypted with AES prior to exfiltration and sent to hardcoded C2 addresses.
First reported: 04.03.2026 21:063 sources, 6 articlesShow sources
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The implant includes a domain generation algorithm (DGA) seeded with the string 'lazarus' that produces .xyz domains.
First reported: 04.03.2026 21:062 sources, 5 articlesShow sources
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks — www.bleepingcomputer.com — 04.03.2026 21:06
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The Coruna exploit kit includes a binary loader that deploys the final stage of the attack after the initial browser exploit succeeds.
First reported: 05.03.2026 14:153 sources, 4 articlesShow sources
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The exploit kit uses custom encryption and compression methods to deliver payloads.
First reported: 05.03.2026 14:153 sources, 4 articlesShow sources
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The exploit kit is ineffective against the latest iOS versions.
First reported: 05.03.2026 14:153 sources, 5 articlesShow sources
- Coruna Exploit Kit Targets Older iPhones in Multi-Stage Campaigns — www.infosecurity-magazine.com — 05.03.2026 14:15
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
CISA added three of the 23 Coruna vulnerabilities to its catalog of Known Exploited Vulnerabilities.
First reported: 06.03.2026 17:572 sources, 5 articlesShow sources
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
Coruna provides threat actors with Pointer Authentication Code (PAC) bypass, sandbox escape, and PPL (Page Protection Layer) bypass capabilities.
First reported: 06.03.2026 17:572 sources, 4 articlesShow sources
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Coruna enables threat actors to gain WebKit remote code execution and escalate permissions to Kernel privileges on vulnerable devices.
First reported: 06.03.2026 17:572 sources, 4 articlesShow sources
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
CISA ordered federal agencies to patch the vulnerabilities by March 26, 2026, as mandated by the Binding Operational Directive (BOD) 22-01.
First reported: 06.03.2026 17:572 sources, 5 articlesShow sources
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
CISA urged all organizations, including private sector companies, to prioritize patching these flaws to secure their devices against attacks as soon as possible.
First reported: 06.03.2026 17:572 sources, 5 articlesShow sources
- CISA warns of Apple flaws exploited in spyware, crypto-theft attacks — www.bleepingcomputer.com — 06.03.2026 17:57
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
Apple backported fixes for CVE-2023-43010 to older iOS versions to address vulnerabilities used in the Coruna exploit kit.
First reported: 12.03.2026 11:582 sources, 4 articlesShow sources
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
The vulnerability CVE-2023-43010 relates to an unspecified vulnerability in WebKit that could result in memory corruption when processing maliciously crafted web content.
First reported: 12.03.2026 11:582 sources, 4 articlesShow sources
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
The fix for CVE-2023-43010 was originally shipped in iOS 17.2 on December 11th, 2023.
First reported: 12.03.2026 11:582 sources, 4 articlesShow sources
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
The latest round of fixes brings the vulnerability patch to older versions of iOS and iPadOS, including iOS 15.8.7 and iPadOS 15.8.7, and iOS 16.7.15 and iPadOS 16.7.15.
First reported: 12.03.2026 11:582 sources, 4 articlesShow sources
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
iOS 15.8.7 and iPadOS 15.8.7 incorporate patches for three more vulnerabilities associated with the Coruna exploit: CVE-2023-43000, CVE-2023-41974, and CVE-2024-23222.
First reported: 12.03.2026 11:582 sources, 3 articlesShow sources
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
Coruna may have been designed by U.S. military contractor L3Harris and passed to Russian exploit broker Operation Zero by Peter Williams.
First reported: 12.03.2026 11:581 source, 1 articleShow sources
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
-
Coruna uses two exploits (CVE-2023-32434 and CVE-2023-38606) that were weaponized as zero-days in a campaign dubbed Operation Triangulation targeting users in Russia in 2023.
First reported: 12.03.2026 11:581 source, 2 articlesShow sources
- Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit — thehackernews.com — 12.03.2026 11:58
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
Apple has released security updates to patch older iPhones and iPads against vulnerabilities targeted by the Coruna exploit kit.
First reported: 12.03.2026 15:431 source, 2 articlesShow sources
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The patches address vulnerabilities CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, and CVE-2023-43010.
First reported: 12.03.2026 15:431 source, 2 articlesShow sources
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The affected devices include iPhone 6s (all models), iPhone 7 (all models), iPhone SE (1st generation), iPhone 8, iPhone 8 Plus, iPhone X, iPad Air 2, iPad mini (4th generation), iPod touch (7th generation), iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation.
First reported: 12.03.2026 15:432 sources, 3 articlesShow sources
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The Coruna exploit kit has been used by multiple threat groups, including a suspected Russian state-backed hacking group (UNC6353), a surveillance vendor customer, and a financially motivated Chinese threat actor (UNC6691).
First reported: 12.03.2026 15:433 sources, 6 articlesShow sources
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
UNC6691 deployed the exploit kit on fake gambling and crypto websites to deliver malware payloads that stole cryptocurrency wallets from infected victims' devices.
First reported: 12.03.2026 15:432 sources, 5 articlesShow sources
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
CISA added three of the 23 vulnerabilities targeted by Coruna to its catalog of Known Exploited Vulnerabilities, including CVE-2023-43010.
First reported: 12.03.2026 15:432 sources, 3 articlesShow sources
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
CISA ordered Federal Civilian Executive Branch (FCEB) agencies to patch their iOS devices by March 26, 2026, as mandated by the Binding Operational Directive (BOD) 22-01.
First reported: 12.03.2026 15:432 sources, 3 articlesShow sources
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Apple has also fixed a zero-day vulnerability (CVE-2026-20700) exploited in an "extremely sophisticated attack" targeting specific individuals and allowing threat actors to execute arbitrary code on compromised devices.
First reported: 12.03.2026 15:431 source, 1 articleShow sources
- Apple patches older iPhones and iPads against Coruna exploits — www.bleepingcomputer.com — 12.03.2026 15:43
-
A new iOS exploit kit named Darksword has been used to steal a wide range of personal information, including data from cryptocurrency wallet apps.
First reported: 18.03.2026 16:022 sources, 3 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword targets iPhones running iOS 18.4 through 18.6.2.
First reported: 18.03.2026 16:022 sources, 3 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits — thehackernews.com — 27.03.2026 19:22
-
Darksword is linked to the likely Russian threat actor UNC6353 behind the Coruna exploit chain.
First reported: 18.03.2026 16:023 sources, 4 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
Darksword was discovered by Lookout Threat Labs in collaboration with Google’s Threat Intelligence Group and iVerify during investigations into Coruna attack infrastructure.
First reported: 18.03.2026 16:022 sources, 3 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
The vulnerabilities exploited by Darksword (CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, CVE-2025-43520) are known, documented, and already fixed by Apple in the latest iOS releases.
First reported: 18.03.2026 16:023 sources, 4 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword uses multiple exploits including type confusion, use-after-free, out-of-bounds write, copy-on-write kernel bugs, and kernel privilege escalation bugs to gain kernel read/write access.
First reported: 18.03.2026 16:023 sources, 4 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword attacks begin via a Safari browser exploit delivering a main orchestrator component (pe_main.js) that injects a JavaScript engine into privileged iOS services such as App Access, Wi-Fi, Springboard, Keychain, and iCloud.
First reported: 18.03.2026 16:023 sources, 4 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword data-stealing modules target saved passwords, photos, WhatsApp and Telegram databases, cryptocurrency wallets (Coinbase, Binance, Ledger, etc.), text messages, address book, call history, location history, browser history, cookies, Wi-Fi history and passwords, Apple Health data, calendar, notes, installed applications, and connected accounts.
First reported: 18.03.2026 16:023 sources, 4 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword wipes temporary files and exits after exfiltrating data, indicating it is not designed for long-term surveillance.
First reported: 18.03.2026 16:023 sources, 4 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Lookout estimates Darksword is used by a Russian threat actor with financial objectives aligning with espionage requirements.
First reported: 18.03.2026 16:023 sources, 5 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
iPhone users are advised to upgrade to iOS 26.3.1 (latest) and enable Lockdown Mode if at high risk of targeting.
First reported: 18.03.2026 16:023 sources, 5 articlesShow sources
- New “Darksword” iOS exploit used in infostealer attack on iPhones — www.bleepingcomputer.com — 18.03.2026 16:02
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
A new iOS exploit chain named DarkSword targets iPhones running iOS versions 18.4 through 18.7, expanding the previously reported target range of iOS 18.4–18.6.2.
First reported: 18.03.2026 23:153 sources, 3 articlesShow sources
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
DarkSword leverages multiple zero-day vulnerabilities including JavaScriptCore memory corruption flaws (CVE-2025-31277 and CVE-2025-43529), dyld user-mode pointer authentication code bypass (CVE-2026-20700), ANGLE memory corruption flaw (CVE-2025-14174), iOS kernel memory management flaw (CVE-2025-43510), and iOS kernel memory corruption bug (CVE-2025-43520).
First reported: 18.03.2026 23:153 sources, 3 articlesShow sources
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
During DarkSword attacks, victims are compromised within seconds to minutes via a malicious website, leading to kernel privilege escalation and rapid data exfiltration before the malware self-wipes.
First reported: 18.03.2026 23:153 sources, 3 articlesShow sources
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
DarkSword has been used in campaigns targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025, with evidence of involvement by commercial surveillance vendors and suspected state-sponsored actors including Turkish surveillance vendor PARS Defense and Russian threat actor UNC6353.
First reported: 18.03.2026 23:153 sources, 3 articlesShow sources
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
DarkSword includes modular malware families tracked as Ghostblade, Ghostknife, and Ghostsaber, used for data theft and espionage purposes.
First reported: 18.03.2026 23:153 sources, 3 articlesShow sources
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Analysis suggests large language model tools were used in the creation of at least some DarkSword implant code, indicating advanced modular design and potential extensibility.
First reported: 18.03.2026 23:153 sources, 4 articlesShow sources
- DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike — www.darkreading.com — 18.03.2026 23:15
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
- Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits — thehackernews.com — 27.03.2026 19:22
-
Darksword has been used in campaigns by at least three distinct threat actors: UNC6353 (Russian espionage group targeting Ukrainian users), UNC6748 (targeting Saudi Arabian users via a Snapchat-themed website), and Turkish surveillance vendor PARS Defense (delivering GHOSTSABER backdoor)
First reported: 19.03.2026 11:142 sources, 3 articlesShow sources
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword targets iOS versions 18.4 through 18.7, expanding the previously reported range of 18.4–18.6.2
First reported: 19.03.2026 11:142 sources, 3 articlesShow sources
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword uses six vulnerabilities (CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, CVE-2025-43520), with three (CVE-2026-20700, CVE-2025-43529, CVE-2025-14174) exploited as zero-days before Apple patches
First reported: 19.03.2026 11:142 sources, 3 articlesShow sources
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword compromises victims in seconds to minutes via malicious websites, achieves kernel read/write via Safari exploit chain, and self-wipes after exfiltrating data including cryptocurrency wallets, emails, messages, location history, health data, and system credentials
First reported: 19.03.2026 11:142 sources, 3 articlesShow sources
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword employs three payloads: GHOSTBLADE (dataminer), GHOSTKNIFE (JavaScript backdoor for UNC6748), and GHOSTSABER (backdoor for PARS Defense), all communicating with external C2 servers over HTTP(S)
First reported: 19.03.2026 11:142 sources, 3 articlesShow sources
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword’s modular JavaScript-based design includes references to older iOS versions (17.4.1, 17.5.1), suggesting code porting from prior iterations
First reported: 19.03.2026 11:142 sources, 3 articlesShow sources
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Darksword’s OPSEC failures include lack of code obfuscation, plainly named components (e.g., ‘File Receiver’), and simple iframe structures, indicating either resource constraints or disregard for operational security among threat actors
First reported: 19.03.2026 11:142 sources, 3 articlesShow sources
- DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover — thehackernews.com — 19.03.2026 11:14
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks — thehackernews.com — 20.03.2026 07:16
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
CISA ordered U.S. government agencies to patch three DarkSword-linked iOS vulnerabilities (CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520) and mandated fixes by April 3, 2026, under Binding Operational Directive (BOD) 22-01, though the directive applies only to federal agencies
First reported: 23.03.2026 10:371 source, 1 articleShow sources
- CISA orders feds to patch DarkSword iOS flaws exploited attacks — www.bleepingcomputer.com — 23.03.2026 10:37
-
Coruna’s kernel exploits are derived from the same codebase used in the 2023 Operation Triangulation campaign, with shared authorship confirmed by Kaspersky GReAT
First reported: 26.03.2026 13:072 sources, 3 articlesShow sources
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
- Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits — thehackernews.com — 27.03.2026 19:22
-
Coruna includes five full iOS exploit chains and 23 total exploits, including CVE-2023-32434 and CVE-2023-38606, which were first weaponized as zero-days in Operation Triangulation
First reported: 26.03.2026 13:072 sources, 2 articlesShow sources
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
Coruna’s exploit framework includes checks for Apple’s A17, M3, M3 Pro, and M3 Max processors and iOS 17.2, indicating active maintenance and expansion of the original Operation Triangulation codebase
First reported: 26.03.2026 13:071 source, 1 articleShow sources
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
-
The starting point of Coruna attacks is a compromised website that fingerprints the browser via a stager, serving exploits based on OS and browser version to trigger kernel execution
First reported: 26.03.2026 13:072 sources, 2 articlesShow sources
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
The payload executes kernel exploits, Mach-O loaders, and malware launchers, with the launcher selecting appropriate loaders based on firmware, CPU, and iokit-open-service permissions
First reported: 26.03.2026 13:072 sources, 2 articlesShow sources
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
The launcher drops and executes the final implant post-exploitation and cleans up exploitation artifacts to remove forensic traces
First reported: 26.03.2026 13:072 sources, 2 articlesShow sources
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
Originally a precision espionage tool, Coruna is now deployed in mass exploitation campaigns, expanding risk to millions of unpatched devices
First reported: 26.03.2026 13:072 sources, 2 articlesShow sources
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
A new version of the DarkSword exploit kit has been leaked on GitHub, raising concerns that it could enable mass exploitation beyond its current target scope
First reported: 26.03.2026 13:073 sources, 3 articlesShow sources
- Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass Attacks — thehackernews.com — 26.03.2026 13:07
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
Coruna's kernel exploit for CVE-2023-32434 and CVE-2023-38606 is explicitly identified as an updated version of the same exploit used in the 2019–2023 Operation Triangulation campaign, confirming continuities in code and authorship.
First reported: 26.03.2026 15:101 source, 1 articleShow sources
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
The exploit framework includes explicit checks for Apple's A17, M3, M3 Pro, and M3 Max chips, indicating active maintenance and targeting of modern hardware beyond original Triangulation scope.
First reported: 26.03.2026 15:101 source, 1 articleShow sources
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
Coruna's stager initiates Safari-based attacks by fingerprinting the device, selecting RCE and PAC exploits, and retrieving encrypted metadata for subsequent payload stages.
First reported: 26.03.2026 15:101 source, 1 articleShow sources
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
The payload delivery chain uses ChaCha20 for decryption and LZMA for decompression before parsing custom container formats to obtain package information.
First reported: 26.03.2026 15:101 source, 1 articleShow sources
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
Coruna supports ARM64 and ARM64E architectures, with package IDs and system checks targeting iOS versions below 14.0 beta 7, 14.7, 16.5 beta 4, 16.6 beta 5, and 17.2.
First reported: 26.03.2026 15:101 source, 1 articleShow sources
- Coruna iOS exploit framework linked to Triangulation attacks — www.bleepingcomputer.com — 26.03.2026 15:10
-
Apple is now sending Lock Screen notifications to outdated iPhones and iPads running older iOS versions warning users of active web-based exploits and urging them to install critical updates.
First reported: 27.03.2026 19:221 source, 1 articleShow sources
- Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits — thehackernews.com — 27.03.2026 19:22
-
Apple released iOS 18.7.7 and iPadOS 18.7.7 on April 1, 2026 to protect devices running iOS 18 from DarkSword exploit kit attacks without requiring a full OS upgrade
First reported: 02.04.2026 16:301 source, 1 articleShow sources
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
The iOS 18.7.7 update makes security patches originally released in 2025 available to users still on iOS 18, enabling protection against DarkSword's six vulnerabilities
First reported: 02.04.2026 16:301 source, 1 articleShow sources
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
Eligible devices for the iOS 18.7.7 update include iPhone XR through iPhone 16 models, iPhone SE (2nd and 3rd generation), multiple iPad mini, iPad Air and iPad Pro models, and iPad (7th generation)
First reported: 02.04.2026 16:301 source, 1 articleShow sources
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
DarkSword exploit kit has been actively used in cyber attacks since July 2025, targeting users in multiple countries through watering hole attacks on compromised websites
First reported: 02.04.2026 16:301 source, 1 articleShow sources
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
DarkSword deploys data-stealing malware including GhostBlade, GhostKnife, and GhostSaber in attacks that silently steal user data upon visiting compromised websites
First reported: 02.04.2026 16:301 source, 1 articleShow sources
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
-
The DarkSword exploit kit was leaked on GitHub, increasing the risk of commoditized exploitation beyond targeted campaigns
First reported: 02.04.2026 16:301 source, 1 articleShow sources
- Apple Expands iOS 18 Security Updates Amid DarkSword Threat — www.infosecurity-magazine.com — 02.04.2026 16:30
Similar Happenings
Background Security Improvements update issued to remediate CVE-2026-20643 WebKit navigation bypass
Apple’s Background Security Improvements update addressed CVE-2026-20643, a WebKit flaw enabling malicious web content to bypass Same Origin Policy restrictions via the Navigation API. The vulnerability impacted iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2, exposing users to data leakage or spoofing risks. The fix was delivered as a lightweight, out-of-band patch via Apple’s Background Security Improvements mechanism, eliminating the need for a full OS upgrade or device restart. Background Security Improvements updates can be managed via Privacy & Security settings, with options for automatic installation and rollback to baseline OS versions if removed.
Increase in Zero-Day Exploits in 2025
Google Threat Intelligence Group (GTIG) reported tracking 90 zero-day vulnerabilities exploited in 2025, a 15% increase from 2024. Nearly half targeted enterprise software and appliances, with 43 (48%) zero-days identified, up from 36 (46%) in 2024. Memory safety issues accounted for 35% of these exploits. Commercial spyware vendors were the largest users of zero-days, surpassing state-sponsored groups. China-linked espionage groups remained the most active among state actors, while financially motivated actors also increased their use of zero-days. The most targeted enterprise systems included security appliances, networking infrastructure, VPNs, and virtualization platforms. Google recommends reducing attack surfaces, continuous monitoring, and rapid patching to mitigate risks.
PCI Security Standards Council Highlights Accelerating Threats to Payment Systems
The PCI Security Standards Council (PCI SSC) released its first annual report, emphasizing the increasing sophistication and speed of threats targeting payment systems. The report underscores the need for global coordination, education, and collaboration to advance payment security across various sectors. Threat actors are increasingly targeting payment cards, point-of-sale systems, and processing systems through methods like skimming, jackpotting, and credential theft. The council's initiatives aim to secure mobile, data, device, software, and card products by updating standards and compliance requirements.
Critical Authentication Bypass in Cisco Catalyst SD-WAN Exploited Since 2023
A critical authentication bypass vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN has been actively exploited in zero-day attacks since at least 2023. The flaw allows remote attackers to compromise controllers and add malicious rogue peers to targeted networks. The vulnerability stems from a peering authentication mechanism that does not work properly, enabling attackers to log in as high-privileged users and manipulate network configurations. Cisco has released specific software updates to address the issue, and CISA has issued an emergency directive requiring federal agencies to patch affected systems by February 27, 2026. Attackers have been found to leverage the built-in update mechanism to stage a software version downgrade and escalate to the root user by exploiting CVE-2022-20775, and have taken steps to clear evidence of the intrusion by purging logs and command history. Additionally, Cisco has flagged two more Catalyst SD-WAN Manager security flaws (CVE-2026-20128 and CVE-2026-20122) as actively exploited in the wild, urging administrators to upgrade vulnerable devices. CVE-2026-20128 is an information disclosure issue affecting the Data Collection Agent (DCA) feature, allowing an authenticated, local attacker to gain DCA user privileges. CVE-2026-20122 is an arbitrary file overwrite bug affecting the API, allowing a remote, authenticated attacker to overwrite arbitrary files and gain elevated privileges. Cisco Talos has linked the attacks exploiting CVE-2026-20127 to UAT-8616, a highly sophisticated threat actor active since at least 2023. Cisco has also released updates to address two maximum-severity vulnerabilities in its Secure Firewall Management Center (FMC) software: CVE-2026-20079 and CVE-2026-20131.
Predator Spyware Hides iOS Recording Indicators via SpringBoard Hooking
Intellexa’s Predator spyware leverages kernel-level access to hook iOS SpringBoard and suppress camera and microphone activity indicators. The malware intercepts sensor activity updates, preventing the display of green or orange dots in the status bar. This allows Predator to operate stealthily, hiding its surveillance activities from users. The spyware exploits previously obtained kernel access rather than zero-day vulnerabilities.