Active Exploitation Alert: Coruna and DarkSword iOS Exploit Chains Target Apple Devices Globally

Active Exploitation Alert: Coruna and DarkSword iOS Exploit Chains Target Apple Devices Globally

Executive Summary

The global proliferation of the Coruna and DarkSword iOS exploit chains marks a significant escalation in mobile cyber threats, with both commercial surveillance vendors and state-sponsored advanced persistent threat (APT) groups leveraging these toolkits to compromise Apple devices at scale. These exploit frameworks utilize sophisticated chains of zero-day and n-day vulnerabilities, enabling full device compromise, persistent surveillance, and exfiltration of sensitive data. Over 17,000 domains have been identified as hosting variants of these exploits, with confirmed targeting in Saudi Arabia, Turkey, Malaysia, and Ukraine. The campaigns demonstrate a high degree of technical sophistication, modularity, and operational security, posing a critical risk to organizations and individuals relying on iOS devices for secure communications and sensitive operations.

Threat Actor Profile

The actors deploying Coruna and DarkSword span both commercial and nation-state domains. UNC6748 is a Saudi Arabia-focused commercial surveillance operator, utilizing social engineering and phishing to deliver payloads. PARS Defense is a Turkish surveillance vendor with operations extending into Malaysia, employing custom phishing infrastructure. UNC6353 is a Russian APT group, previously associated with Coruna and now observed deploying DarkSword in Ukraine, targeting government, military, and civil society entities. These actors exhibit advanced operational tradecraft, including rapid adoption of new exploits, use of obfuscated JavaScript loaders, and robust command-and-control (C2) infrastructure. Their campaigns are characterized by precise targeting, often leveraging regional lures and watering hole attacks to maximize infection rates among high-value targets.

Technical Analysis of Malware/TTPs

DarkSword and Coruna are modular exploit kits designed to compromise iOS devices through multi-stage chains. DarkSword supports iOS versions 18.4 through 18.7, exploiting six distinct vulnerabilities, several of which were zero-day at the time of discovery. The exploit chain typically begins with a remote code execution (RCE) vulnerability in JavaScriptCore (e.g., CVE-2026-31277, CVE-2026-43529), followed by a sandbox escape via ANGLE (WebGL) memory corruption (CVE-2026-14174) or a dyld PAC bypass (CVE-2026-20700). Privilege escalation is achieved through kernel vulnerabilities in XNU (CVE-2026-43510, CVE-2026-43520), culminating in the deployment of JavaScript-based payloads such as GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER.

Coruna served as the precursor to DarkSword, providing five complete exploit chains and acting as a codebase foundation. Both kits employ extensive obfuscation, anti-forensics (including crash log deletion), and modular payload delivery. Payloads are tailored to the target region and actor, with GHOSTBLADE functioning as a dataminer in Ukraine, GHOSTKNIFE as a backdoor in Saudi Arabia, and GHOSTSABER as a backdoor in Turkey and Malaysia. These payloads enable comprehensive device surveillance, including exfiltration of messages, contacts, keychains, WiFi credentials, browser data, health data, and more.

The infection chain is initiated via phishing or watering hole sites hosting obfuscated JavaScript. The loader determines the iOS version and delivers the appropriate RCE exploit, chaining subsequent vulnerabilities to achieve full device compromise. The final payload operates in-memory, minimizing forensic artifacts and maximizing stealth.

Exploitation in the Wild

In Saudi Arabia, UNC6748 leveraged a Snapchat-themed phishing site (snapshare[.]chat) to deliver the GHOSTKNIFE backdoor, exfiltrating user accounts, messages, browser data, geolocation, audio, and screenshots, while deleting crash logs to hinder detection. In Turkey and Malaysia, PARS Defense deployed GHOSTSABER via custom phishing domains (sahibndn[.]io, e5.malaymoil[.]com), enabling device enumeration, file listing, arbitrary JavaScript execution, and data exfiltration. In Ukraine, UNC6353 conducted watering hole attacks on legitimate Ukrainian websites (static.cdncounter[.]net), deploying GHOSTBLADE to extract iMessage, Telegram, WhatsApp, mail, call logs, contacts, keychains, WiFi credentials, photos, Safari data, and health information.

The campaigns are notable for their rapid exploitation of newly discovered vulnerabilities, use of region-specific lures, and deployment of advanced anti-forensics. Over 17,000 domains have been identified as hosting exploit variants, indicating a broad and sustained operational footprint.

Victimology and Targeting

Victimology analysis reveals targeted campaigns against government officials, journalists, activists, and members of civil society in Ukraine, Saudi Arabia, Turkey, and Malaysia. In Saudi Arabia, the focus has been on mass surveillance of the general population via social media-themed lures. In Turkey and Malaysia, the targeting is more selective, focusing on political dissidents and opposition figures. In Ukraine, the targeting is strategic, aimed at government, military, and civil society organizations, consistent with Russian state-sponsored espionage objectives. The use of watering hole attacks in Ukraine demonstrates a high level of sophistication, enabling the compromise of multiple high-value targets through a single vector.

Mitigation and Countermeasures

Immediate mitigation requires updating all iOS devices to version 26.3 or later, as this release patches all known vulnerabilities exploited by DarkSword and Coruna. For users unable to update, enabling Lockdown Mode provides significant mitigation by restricting the attack surface available to exploit chains. Organizations should block known malicious domains and IP addresses at the network perimeter, including snapshare[.]chat, sahibndn[.]io, e5.malaymoil[.]com, static.cdncounter[.]net, and sqwas.shapelie[.]com. Security teams are advised to hunt for YARA rule matches corresponding to GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE artifacts, as published by Google Cloud Threat Intelligence. Monitoring for suspicious or obfuscated JavaScript loading from untrusted domains, particularly on mobile browsers, is critical for early detection. Incident response teams should review device logs for evidence of crash log deletion, anomalous JavaScript execution, and unauthorized data exfiltration. User awareness training on phishing and watering hole threats remains a key defensive measure.

References

Google Cloud Threat Intelligence: DarkSword iOS Exploit Chain

Dark Reading: Coruna, DarkSword iOS Exploits Proliferate Globally

Lookout Threat Intelligence: DarkSword

Wikipedia: Coruna (exploit kit)

Check Point Community: Coruna and DarkSword iOS Exploits

Zimperium: DarkSword, the Hit-and-Run Successor

iVerify: Inside DarkSword

About Rescana

Rescana delivers advanced third-party risk management (TPRM) solutions, empowering organizations to proactively identify, assess, and mitigate cyber threats across their digital supply chain. Our platform leverages real-time threat intelligence, automated risk scoring, and continuous monitoring to provide actionable insights and enhance organizational resilience. For more information or to discuss how Rescana can support your security objectives, we are happy to answer questions at info@rescana.com.