// 1 CRITICAL · 4 ZERO-DAY · 6 CVE · 5 EXPLOIT · 1 ADVISORY IN THE LAST 24H
Apple issued rare retroactive patches for legacy iOS versions to address two APT-grade spyware frameworks now weaponized in zero-click, mass infections against everyday users. Over 42,000 devices compromised in China alone.

Kaspersky GReAT published its discovery of DarkSword and Coruna on April 17, 2026 — two iOS attack frameworks that transpose the government spyware model into mass infections targeting ordinary users. Apple responded with retroactive patches for iOS 15.8.7, 16.7.15, and 18.7.7, an exceptional move that underscores the severity of the threat. The stakes have moved beyond political espionage: the motive is now crypto wallet theft, making every user on an unpatched iOS version an economic target.

Key Takeaways
  • DarkSword exploits a chain of 6 iOS vulnerabilities for sandbox escape, privilege escalation, and code execution; Coruna employs 23, several in WebKit, to compromise versions from iOS 13 through iOS 17.2.1
  • Both operate in zero-click mode: compromise occurs simply by visiting infected legitimate sites, with no user interaction required
  • DarkSword is fileless malware residing in RAM that does not survive a reboot; Coruna is an updated version of the framework used in Operation Triangulation, with four additional kernel exploits developed after that operation's discovery
  • Apple confirmed both tools in its own patch notes: iOS 18.7.7 explicitly cites "web attacks called DarkSword," while iOS 15.8.7 and 16.7.15 associate fixes with "the Coruna exploit"

The Mechanism: From Watering Hole to Sandbox Escape Without a Click

The attack originates from legitimate sites compromised with injected malicious code. The victim visits the site — via Safari or any iOS browser, all forced to use WebKit by Apple's mandate — and the code exploits vulnerabilities in the rendering engine to gain initial execution. From there, the exploit chains diverge.

DarkSword employs 6 vulnerabilities in sequence to escape the sandbox, escalate privileges, and execute arbitrary code, according to Kaspersky GReAT analysis. The final payload is fileless: it resides in RAM, leaves minimal filesystem traces, and disappears on device reboot. This architecture reduces post-infection forensic detectability, though it does not guarantee persistence beyond a reboot.

Coruna is more complex: 23 distinct vulnerabilities, "several of which are tucked away in Apple's WebKit," per the same source. Kaspersky describes the framework on SecureList as "an updated version of the same exploit that had been used in Operation Triangulation," with four additional kernel exploits, two of which were developed after the discovery of that operation. Technical analysis highlights stagers with browser fingerprinting, conditional RCE and PAC exploits, payloads encrypted with ChaCha20 and compressed with LZMA, and containers identified by the magic numbers 0xBEDF00D, 0xF00DBEEF, and 0x12345678. The code is "uniformly engineered," not a patchwork of stolen components.

Apple's Trail: Retroactive Patches as a Crisis Barometer

On April 1, 2026, Apple retroactively enabled iOS 18.7.7, per its support documentation. This rare move to support obsolete versions — iOS 15.8.7 and 16.7.15 were patched simultaneously — signals the vendor assessed the threat as too severe to leave behind devices unable to upgrade to iOS 26.

The advisory for iOS 18.7.7 explicitly states "users with Automatic Updates turned on can automatically receive important security protections from web attacks called DarkSword" and adds: "The fixes associated with the DarkSword exploit first shipped in 2025." This note clarifies the vulnerabilities were already patched in mainline releases, but the retroactive backporting indicates an in-the-wild campaign extensive enough to justify the exception.

For Coruna, iOS 15.8.7 reports "This fix associated with the Coruna exploit was shipped in iOS 17 on September 18, 2023. This update brings that fix to devices that cannot update," while iOS 16.7.15 specifies "This fix associated with the Coruna exploit was shipped in iOS 17.2 on December 11th, 2023." The same vulnerability, therefore, required three years of latency for complete backporting — an interval that exposes Apple's support architecture as a potential weakness in the "closed and trusted" model.

Democratization of the Threat: From Dissidents to Crypto Wallets

"DarkSword and Coruna — discovered by researchers earlier this year — are total game-changers. This malware is being used for mass infections of everyday users." — Kaspersky GReAT

The qualitative shift is not technical but economic. Operation Triangulation, discovered by Kaspersky in 2023, specifically targeted the company's own employees and high-risk figures. DarkSword and Coruna strike "everyday users" for profit: crypto wallet theft. Kaspersky estimates at least 42,000 devices were infected in China "there alone" by Coruna, an order of magnitude that transforms spyware from an intelligence tool into a scalable criminal commodity.

DarkSword hit users in Saudi Arabia, Turkey, and Malaysia, per the same source. On some infected sites, researchers found the framework's full source code, a detail that facilitates replication and modification by less sophisticated operators. The origin remains attributed to "software originally created by state-affiliated companies, possibly from the U.S." — the high code quality, detailed English comments, and uniform engineering support this hypothesis — but no documented infrastructure overlaps link the actor to a specific government agency at this time.

The precise leakage mechanism is unconfirmed: an unverified theory suggests sale by an insider, but the dossier offers no proof. What is documented is the result: government-grade APT tooling now operational in the hands of common cybercriminals.

Apple's Bind: When the Closed Model Meets Universal Vulnerabilities

Apple's architectural choice — mandatory WebKit for all iOS browsers, strict sandbox, centralized software distribution — is designed to reduce the attack surface. The paradoxical effect is that a WebKit vulnerability becomes universal: Chrome, Firefox, Brave, or any alternative on iOS are all vulnerable simultaneously, because they all use Apple's engine.

Coruna and DarkSword exploit exactly this constraint. Coruna's 23 vulnerabilities and DarkSword's 6 include flaws affecting the shared web rendering, turning every visited page into a potential vector. The "trusted" security model therefore requires absolute trust in the vendor for patch timeliness — trust that the three-year backporting for Coruna, and the retroactive enablement on April 1, 2026 for DarkSword, place under tension.

Kaspersky's estimate that roughly 25% of active Apple devices still run iOS 18 or earlier translates the vulnerability into market scale: millions of potentially exposed devices, not by conscious choice but by hardware obsolescence or delayed automatic updates.

What to Do Now

Apple has released specific, structured patches: users on iOS 15, 16, or 18 must verify they have received iOS 15.8.7, 16.7.15, or 18.7.7 respectively. The iOS 18.7.7 advisory specifies that "users with Automatic Updates turned on can automatically receive important security protections," suggesting the automatic update mechanism is the primary distribution vector for these retroactive patches.

Devices that do not support iOS 26 remain exposed if not updated to the retroactive patches: iOS 15.8.7 and 16.7.15 were explicitly released for "devices that cannot update" to the mainline. Users of these devices must manually check for the update, as automatic notification may be delayed.

The zero-click nature of the attack — compromise via visit to an infected legitimate site — renders the usual cautions about clicking ineffective. The brief documents no specific remedial measures beyond OS updates: the source does not specify whether alternative browsers or network restrictions can mitigate the threat, nor whether there are compromise indicators detectable by the end user.

The dossier lists no corrective actions by Kaspersky or other endpoint security vendors for iOS, a platform that restricts installation of third-party software with system-level access.

The Remaining Risk: Abandoned Devices and the Gray Exploit Market

The sharpest dividing line is not technical but economic. iOS 15.8.7 covers devices Apple has formally retired from mainline support; the patch is an emergency-driven exception, not a policy. If Apple's business model entails planned obsolescence of security support, every future leak of APT tooling risks finding a population of "zombie" devices with no patches available.

The dossier does not specify whether other vulnerabilities from the same set remain unpatched, nor whether the criminal groups using DarkSword and Coruna possess modified variants that evade the retroactive fixes. The presence of exposed source code on infected sites makes this hypothesis technically plausible, but undocumented in current sources.

The consolidated narrative of iOS spyware as the preserve of executives and activists has slowed threat perception among ordinary users. The shift to crypto wallet theft as the primary motive eliminates this imaginative distance: the target is now anyone holding digital assets, a significantly larger population less accustomed to advanced persistent threat models.

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. kaspersky.com
  2. support.apple.com
  3. securelist.com