Executive Summary
In early 2026, Apple identified and patched critical vulnerabilities in iOS that were actively exploited by sophisticated exploit kits, notably 'Coruna' and 'DarkSword'. These kits targeted older iPhone models running outdated iOS versions, enabling attackers to execute arbitrary code and steal sensitive data through malicious web content. The 'Coruna' exploit kit, in particular, contained 23 exploits spanning four years of iOS versions, posing a significant threat to users who had not updated their devices. (macrumors.com)
The exploitation of these vulnerabilities underscores the evolving tactics of cybercriminals and the importance of timely software updates. The incidents highlight the necessity for organizations and individuals to maintain up-to-date systems to mitigate the risk of such sophisticated attacks.
Why This Matters Now
The active exploitation of these vulnerabilities demonstrates the increasing sophistication of cyber threats targeting mobile devices. Ensuring that all devices are updated to the latest software versions is crucial to protect against such advanced exploit kits and safeguard sensitive information.
Attack Path Analysis
The attack began when users visited malicious websites hosting the Coruna exploit kit, which identified device details and executed a tailored exploit chain to gain initial access. The exploit kit then escalated privileges by bypassing iOS security features, allowing deeper system access. With elevated privileges, the malware moved laterally within the device to access sensitive applications and data. It established command and control by communicating with external servers to receive further instructions. The malware exfiltrated sensitive data, including cryptocurrency wallet information, to attacker-controlled servers. Finally, the attackers used the stolen data to conduct unauthorized transactions, leading to financial loss for the victims.
Kill Chain Progression
Initial Compromise
Description
Users visited malicious websites hosting the Coruna exploit kit, which identified device details and executed a tailored exploit chain to gain initial access.
Related CVEs
CVE-2025-31277
CVSS 8.8A memory corruption vulnerability in the dyld component allows an attacker to execute arbitrary code with kernel privileges.
Affected Products:
Apple iOS – 18.4, 18.5, 18.6, 18.7
Exploit Status:
exploited in the wildCVE-2026-20700
CVSS 7.8A memory corruption issue in the dyld component allows an attacker to execute arbitrary code with kernel privileges.
Affected Products:
Apple iOS – 18.4, 18.5, 18.6, 18.7
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploitation for Client Execution
Exploit OS Vulnerability
Valid Accounts
File and Directory Discovery
Command and Scripting Interpreter: AppleScript
Event Triggered Execution: Unix Shell Configuration Modification
Hide Artifacts: Hidden Files and Directories
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities by installing applicable security patches
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Mobile app developers face exploit kit targeting older iOS versions, requiring enhanced egress security and zero trust segmentation for development environments.
Financial Services
Banking mobile applications vulnerable to Coruna/DarkSword exploit kits on outdated iOS devices, compromising sensitive financial data through web-based attacks.
Health Care / Life Sciences
Healthcare mobile apps on older iPhones exposed to exploit kit attacks, threatening HIPAA compliance and patient data through malicious web content.
Consumer Electronics
Apple device ecosystem faces direct exploit kit vulnerabilities requiring multicloud visibility and threat detection capabilities for comprehensive device security management.
Sources
- Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attackshttps://thehackernews.com/2026/03/apple-warns-older-iphones-vulnerable-to.htmlVerified
- More than 220 million iPhones under attack from new DarkSword exploit - how to stay safehttps://www.tomsguide.com/phones/iphones/more-than-220-million-iphones-under-attack-from-new-darksword-exploit-how-to-stay-safeVerified
- This new DarkSword iOS exploit can steal almost everything from your iPhone - here's what we knowhttps://www.techradar.com/pro/security/this-new-darksword-ios-exploit-can-steal-almost-everything-from-your-iphone-heres-what-we-knowVerified
- Security Alert: Apple Security Updates - March 2026https://cyber.gov.rw/updates/article/security-alert-apple-security-updates-march-2026/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the malware's ability to escalate privileges, move laterally, establish command and control, and exfiltrate sensitive data, thereby reducing the attack's overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The CNSF may have limited the exploit kit's ability to gain initial access by enforcing strict network segmentation and identity-aware policies.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation could have limited the malware's ability to escalate privileges by enforcing least-privilege access controls.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely have constrained the malware's lateral movement by monitoring and controlling internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control may have limited the malware's ability to establish command and control channels by monitoring and controlling outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement could have limited data exfiltration by enforcing strict outbound traffic policies.
The implementation of Aviatrix Zero Trust CNSF would likely have reduced the scope of data exfiltration, thereby limiting the potential financial impact on victims.
Impact at a Glance
Affected Business Functions
- Personal Data Management
- Financial Transactions
- Communication Services
Estimated downtime: N/A
Estimated loss: N/A
Sensitive user data including cryptocurrency information, browser history, saved passwords, signed-in accounts, and photos.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline intrusion prevention systems (IPS) to detect and block exploit attempts targeting known vulnerabilities.
- • Enforce zero trust segmentation to limit lateral movement within devices and networks.
- • Utilize egress security and policy enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Enhance threat detection and anomaly response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch devices to mitigate vulnerabilities exploited by known exploit kits.



