iPhone Spyware Tools Spread From Spies to Cybercriminals

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Google, iVerify, and Lookout researchers uncovered two iPhone hacking toolkits in the past month — Coruna and DarkSword — both exploiting iOS vulnerabilities to infect devices without any user clicks or downloads.
- Coruna was originally built for a government customer and later ended up in the hands of a Chinese cybercriminal group, while TechCrunch reported defense contractor L3Harris created the spyware for the U.S. government.
- DarkSword, linked to a Russian-based hacking group, was deployed on Ukrainian news and government websites as a watering hole attack, exfiltrating iMessage, WhatsApp, and Telegram messages, location data, contacts, call histories, and browser history.
- DarkSword's developers left the underlying JavaScript code unobscured on the server, meaning even low-level cybercriminals can copy and reuse the tool for a broader range of targets.
- Apple patched the underlying iOS vulnerabilities through recent OS updates, rolled out an emergency software update for older devices, and enabled Safari to block the malicious URL domains identified in the research.
- Lookout researchers suspect DarkSword's developers used a large language model to help build parts of the kit, citing a data exfiltration file simply labeled "DarkSword file receiver" — a naming convention no experienced offensive operator would leave exposed.
- Apple's Lockdown Mode would have blocked all of Coruna and parts of DarkSword, per iVerify, though researchers caution there is no foolproof defense against watering hole attacks and recommend updates and third-party mobile security tools as additional mitigation.
Why it matters: The commercial spyware ecosystem has turned tools once reserved for state intelligence operations targeting activists and journalists into commodities available to ordinary cybercriminals, shattering the marketing promise that iPhones are categorically safer. Any iPhone user who visits a compromised site — including Ukrainian news outlets — can now have messages, photos, location, and contacts silently exfiltrated, forcing Apple's privacy-conscious user base to adopt Lockdown Mode and mobile security tools they previously had no reason to use.



