Coruna and DarkSword, two iOS exploit chains once tied to higher-end operations, are now turning up on about 17,000 domains, according to iVerify. Researchers say the chains have kept spreading months after public disclosure and are no longer staying in nation-state hands.
The key shift is reuse: attackers do not need to build a fresh iPhone break when a working chain can be cloned onto copycat domains and tweaked. iVerify says some variants now mix techniques from both frameworks, with stronger anti-analysis, new persistence, and implants aimed at Telegram and other follow-on abuse, which makes credential and wallet theft easier to industrialize.
If your users depend on iPhones for executive access, crypto custody, or approval flows, this moves the risk from rare surveillance tooling to a broader phishing-and-exploit campaign that can be aimed at the same high-value accounts again and again.