TechnicalNews

PP124: How Coruna, DarkSword, and Other Exploits Slice Up Apple iPhones

The podcast discusses sophisticated iOS exploit frameworks Karuna and DarkSword that have evolved from state-sponsored tools into widely-available threats used by criminals. These exploits achieve kernel-level access, dump encrypted keychains, and persist across reboots, requiring fundamental changes to how enterprises approach mobile security beyond traditional patching and lockdown mode.

Summary

Drew Connery-Murray interviews Akili Akerage, a mobile security expert, to discuss two major iOS exploit frameworks: Karuna and DarkSword. Karuna originated from Operation Triangulation in 2023, reportedly developed by U.S. government contractors at an estimated cost of $30-40 million. It contains 23 different exploits and was observed progressing from government surveillance in 2025 to use against Ukraine by Russians, then to Chinese criminal organizations by end of 2025. DarkSword, containing 6 exploits (3 of which are zero-days), was first observed in 2025 targeting Saudi Arabia and Turkish users before being leaked across 126 GitHub repositories.

Both frameworks operate through one-click watering hole attacks on legitimate websites. They exploit WebKit vulnerabilities using just-in-time (JIT) JavaScript compilation to bypass sandboxes and achieve kernel-level code execution. Once at kernel level, they inject payloads into privileged processes, dump and decrypt the device's keychain to steal credentials, and operate entirely in memory, making detection extremely difficult. Karuna performs cleanup operations after compromise, while DarkSword focuses on broad espionage collection including messages, photos, WhatsApp conversations, and keychains.

Akerage explains how exploits leak from government contractors through insider threats (like L3 Harris employee Peter Williams, who sold 8 exploits for $1.3 million), external theft, and nation-state trading with criminal organizations. He emphasizes that these threats now converge into "Darkuna," which achieves full kernel compromise in three minutes, survives device reboots (unlike its predecessors), improves virtualization detection, and was identified on 17,000 different domains as of the podcast's recording.

Regarding Apple's security posture, Akerage argues that while Apple built a strong walled garden historically, the company cannot keep pace with threat evolution and needs to open APIs to security vendors similar to how macOS has the Endpoint Security Framework. Lockdown mode, while useful, severely reduces device functionality and must be enabled before exploitation occurs.

Akerage outlines seven critical defense recommendations: (1) establish baseline visibility across all devices, not just executives; (2) audit and restrict mobile device access based on identity and permissions; (3) implement MAM and MDM; (4) build a loaner device bench for rapid replacement of compromised devices; (5) establish executive protection programs prioritizing CISOs and global admins as top targets; (6) monitor identity activity; and (7) adopt new technology solutions like mobile EDR, behavioral analysis tools, and AI-augmented security rather than relying on signature-based detection. He emphasizes that AI is accelerating both attack and defense capabilities, and that old security practices anchored to pre-AI methodologies are insufficient.

About this episode

Coruna and DarkSword are exploit frameworks that have successfully targeted Apple iPhones to steal cryptocurrency and harvest data including messages, email, location data, and browsing history. On today&#8217;s show we trace the provenance of these exploits (Coruna was originally developed by a contractor for the US government), their rapid evolution in the cyber underworld, and<a class="excerpt-read-more" href="https://packetpushers.net/podcasts/packet-protector/pp124-how-coruna-darksword-and-other-exploits-slice-up-apple-iphones/" title="ReadPP124: How Coruna, DarkSword, and Other Exploits Slice Up Apple iPhones">... Read more &#187;</a>

Key Insights

  • Karuna was developed at an estimated cost of $30-40 million by U.S. government contractors and progressed from government surveillance use in 2025 to Russian military use against Ukraine to Chinese criminal organizations within a single year.
  • DarkSword contains 3 zero-day exploits and was leaked across 126 public GitHub repositories, making it freely available to any threat actor with basic technical knowledge.
  • Both Karuna and DarkSword exploit WebKit's just-in-time JavaScript compilation feature that Apple intentionally left open for performance reasons, which threat actors now use to bypass security sandboxes.
  • Darkuna, the convergence of Karuna and DarkSword, achieves complete kernel compromise in approximately three minutes and establishes persistence that survives device reboots, eliminating the previous silver bullet of forcing a restart to remove infection.
  • Keychain decryption occurs directly on the device at kernel level, meaning all stored credentials for corporate resources, cryptocurrency wallets, and personal accounts are compromised simultaneously if a device is infected.
  • Insider threat remains a primary vector for exploit leakage, exemplified by L3 Harris employee Peter Williams selling eight government exploits for $1.3 million when their replacement cost was estimated at $40 million.
  • Lockdown mode requires activation before a one-click exploit is clicked, severely restricts device functionality including JIT, message links, FaceTime, and MDM profile installation, making it impractical for most enterprise users.
  • Darkuna was identified on 17,000 different domains as of the podcast recording, representing an unprecedented scale of watering hole attack distribution far exceeding historical threat campaigns.

Topics

iOS exploit frameworks (Karuna, DarkSword, Darkuna)Kernel-level compromise and sandbox escape techniquesState-sponsored tool proliferation to criminal actorsKeychain extraction and credential theftWatering hole attacks and malicious domain distributionApple's security model limitationsLockdown mode effectiveness and trade-offsMobile threat defense (MTD) and mobile EDR strategiesZero-day exploitation and persistence mechanismsEnterprise mobile security recommendationsAI acceleration of threats and defensesIdentity and access management for mobile devices

Transcript

Welcome to Packet Protector, the podcast at the intersection of networking and security. I'm Drew Connery-Murray. JJ is in the tropics somewhere, I hope, sipping an umbrella drink, well-deserved. Today we're going to dive into some iOS exploit frameworks, including Karuna and Darksword. They were designed to steal cryptocurrency and harvest data including messages, emails, location history, browsing history, and more. These frameworks came to light in early 2026. They attracted the attention of the security community for a couple of reasons. First, they were successfully compromising Apple iPhones, which I always assumed was a harder target than other mobile platforms, but that's one of the things we're going to talk about. Second, security researchers strongly suggested that the Karuna…

Full transcript available for MurmurCast members

Sign Up to Access

More from The Everything Feed - All Packet Pushers Pods

Get AI summaries like this delivered to your inbox daily

Get AI summaries delivered to your inbox

MurmurCast summarizes your YouTube channels, podcasts, and newsletters into one daily email digest.