News Room
16
Share
Proliferation of 'Coruna' and 'DarkSword' iOS Exploit Kits Signals Shift in Mercenary Spyware Market
criticalOffensive Tools

Proliferation of 'Coruna' and 'DarkSword' iOS Exploit Kits Signals Shift in Mercenary Spyware Market

Sophisticated iOS exploit kits, previously reserved for nation-state espionage, are being widely distributed via commercial exploit brokers. This democratization of high-tier surveillance tools poses a critical threat to global mobile security.

12 August 2026Last updated 18 August 20265 min readGoogle Threat Intelligence Group (GTIG)
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Offensive Tools
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
High Confidence
Source:
Google Threat Intelligence Group (GTIG)
Read Time:
5 min

Executive Summary

As of August 12, 2026, recent intelligence from the Google Threat Intelligence Group (GTIG) and iVerify indicates a significant shift in the offensive cyber landscape. Two major iOS exploit kits, 'Coruna' and 'DarkSword,' have transitioned from highly targeted nation-state tools to broader commercial availability. These kits, which leverage multiple zero-day vulnerabilities, are now being utilized by a wider array of threat actors, including cybercriminal syndicates and smaller-tier intelligence agencies. This trend highlights the growing influence of commercial exploit brokers in bypassing traditional security perimeters and democratizing advanced surveillance capabilities.

Threat Analysis

The primary driver behind this proliferation is the emergence of a mature commercial zero-day economy. Brokers such as the Russian-based Operation Zero (also known as Matrix) have been identified as central hubs for the acquisition and resale of these tools. Unlike traditional malware, these exploit kits are designed for 'zero-click' or 'one-click' delivery, often requiring no user interaction to compromise a device. The Amnesty International Security Lab reports that the evolution of these systems allows for persistent surveillance even after device reboots, making them exceptionally difficult to detect and remediate.

Technical Details

The 'Coruna' exploit kit is particularly notable for its complexity, containing 23 vulnerabilities across five distinct exploit chains. Attackers have been observed injecting malicious code into legitimate websites—ranging from retail to industrial services—using hidden iFrames hosted on domains like cdn.uacounter[.]com. When a target visits a compromised site, the kit performs a browser-based check to confirm the device is an iPhone before triggering the exploit chain. Similarly, the DarkSword kit has been deployed via phishing lures and compromised web infrastructure, specifically targeting unpatched iOS builds to gain root-level access and deploy surveillance payloads.

Attribution Assessment

Attribution for these tools is increasingly complex due to the involvement of third-party brokers. While 'Coruna' was initially linked to Russian state actors targeting Ukrainian infrastructure, recent evidence suggests the underlying code may have originated from Western defense contractors. The conviction of a former L3Harris executive for selling zero-days to Operation Zero underscores the porous nature of the offensive tool market. This 'gray market' allows nation-state grade tools to flow between geopolitical rivals and commercial entities with minimal oversight.

Implications

The availability of kits like Coruna and DarkSword means that high-end mobile surveillance is no longer the exclusive domain of top-tier intelligence agencies. This poses a severe risk to journalists, activists, and corporate executives globally. Furthermore, the rise of offensive AI is expected to further automate the discovery of new vulnerabilities, potentially shortening the lifecycle of security patches and increasing the frequency of zero-day exploitations.

Recommendations

To mitigate these threats, organizations and high-risk individuals should:

  1. Enable Apple's Lockdown Mode: This significantly reduces the attack surface by disabling complex web features often used by exploit kits.
  2. Enforce Rapid Patching: Utilize Mobile Device Management (MDM) to ensure all devices are running the latest iOS versions immediately upon release.
  3. Monitor for IOCs: Security teams should scan network traffic for known exploit delivery domains such as cdn.uacounter[.]com and other infrastructure identified by Citizen Lab.
  4. Implement Hardware-Based Security: Use physical security keys for MFA to prevent credential theft even if a device is partially compromised.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo