Researchers at Google have identified a sophisticated iPhone exploit framework called DarkSword, active since November 2025, that chains together multiple zero-day vulnerabilities to compromise iOS devices. The discovery follows recent reporting on a comparable toolkit, Coruna, leveraged by both state-affiliated threat actors and cybercriminals. Where Coruna relied on a broader variety of infection vectors, DarkSword is distinguished by its sequential chaining of six discrete vulnerabilities to achieve remote code execution and malware deployment.
The vulnerability chain targets critical subsystems within Apple’s software stack. Three CVEs affect WebKit, the browser engine underpinning Safari and all third-party iOS browsers. Two additional flaws reside in the XNU kernel, shared across iOS and macOS, while the sixth targets dyld, the dynamic linker responsible for loading shared libraries at runtime. Apple addressed all six — CVE-2025-31277, CVE-2025-43529, CVE-2025-14174, CVE-2025-43510, CVE-2025-43520, and CVE-2026-20700 — across a series of patches released between July 2025 and February 2026, though several were being actively exploited in the wild prior to remediation.
The operation was attributed after researchers identified infrastructure overlaps with known threat actors — specifically, a previously flagged malicious domain embedded within compromised legitimate Ukrainian websites. These sites served exploit code through hidden iframes. Notably, the attack chain incorporated a fingerprinting stage that profiled the visiting device, restricting delivery to specific iOS versions. Forensic analysis confirmed that DarkSword functions as a full exploit-plus-infostealer package: it achieves a sandbox escape via WebKit, then leverages GPU-based techniques to inject into kernel space, ultimately gaining full ring-0 control. From there, it bypasses system integrity protections, traverses private directory structures, and exfiltrates data to attacker-controlled infrastructure.
Once persistent on a device, the malware orchestrates multiple components to harvest credentials, cryptographic keys, and personal files, staging the collected data locally before transmitting it to command-and-control servers. Several distinct campaigns have been attributed to the framework, including activity by UNC6748, which used spearphishing via social media platforms. Victims were identified across Turkey, Malaysia, and Ukraine. In select intrusions, DarkSword was deployed alongside a secondary payload with broader data-theft capabilities, targeting account credentials, application data, geolocation history, and cryptocurrency wallet contents.
Analysts assess with moderate-to-high confidence that the operators behind these campaigns have access to commercial-grade offensive tooling, likely procured from exploit brokers or surveillance-as-a-service vendors. The use of a six-zero-day chain signals significant financial resources and technical sophistication. Notably, both DarkSword and Coruna exhibit dual-use characteristics — combining espionage capabilities with financial theft, particularly targeting cryptocurrency assets — reflecting increasing convergence between the objectives of nation-state actors and financially motivated threat groups.
The broader risk to end users stems from the potential proliferation of these capabilities to lower-tier threat actors. An estimated hundreds of millions of devices remain on unpatched iOS versions, leaving them exposed. Researchers strongly recommend updating to the latest iOS release as the primary mitigation. For users on devices that cannot receive updates, enabling Lockdown Mode is advised, as it significantly reduces the attack surface by disabling features commonly abused in browser-based and social engineering exploit chains.
Confident that your data is free from hidden threats? Confident that your data is free from hidden threats? FileDNA and ObtainDNA provide deep file inspection, content disarm and reconstruction and secure data extraction to proactively harden your environment against embedded malware and covert payloads. Engineered for organizations that demand assurance beyond the detection-based limitations of traditional antivirus, our solutions perform structural analysis of file formats, metadata parsing, and embedded object inspection to identify and neutralize attack vectors that signature-based tools routinely miss. From inbound email attachments and shared documents to data in transit, we validate, sanitize, and reconstruct content at the file level — ensuring that only verified, clean data reaches your users and critical infrastructure. Your security team gains full-spectrum visibility and granular control over file-borne risk, with zero disruption to existing workflows.