Observed Signal · Mar 23, 2026 · Exploit Leak · Source: techcrunch · Impact: 4/5 · Sentiment: Negative
DarkSword iPhone Exploit Kit Leaked on GitHub
Researchers say a newer version of DarkSword, an advanced iPhone exploit kit, was publicly uploaded to GitHub, enabling easy reuse by attackers. Security firms iVerify, Google and Lookout report the samples are simple HTML/JavaScript that can be copied and hosted quickly and successfully target devices running iOS 18 or earlier. A security hobbyist demonstrated a successful compromise of an iPad mini on iOS 18. Apple said it is aware of the exploit and issued an emergency update on March 11 for devices that cannot run newer iOS releases, and noted up-to-date devices and Lockdown Mode are not at risk. According to Apple numbers cited, about one-quarter of active iPhones and iPads run iOS 18 or earlier — out of more than 2.5 billion active devices — leaving potentially hundreds of millions vulnerable. DarkSword was previously linked to campaigns against Ukrainian targets; the discovery follows another toolkit called Coruna.
Public release of a working iPhone exploit kit that affects devices running older iOS versions risks mass compromise of hundreds of millions of devices and prompted an emergency update from Apple.
Track GitHub Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- A newer version of the DarkSword iPhone exploit kit was published on GitHub.
- Researchers (iVerify, Google, Lookout) say the leaked samples are simple HTML/JavaScript that can be reused easily and require no iOS expertise.
- DarkSword targets iPhones and iPads running iOS 18 or earlier; Apple reports about one-quarter of devices remain on those versions.
- Apple issued an emergency update on March 11 for devices unable to run recent iOS versions and said updated devices and Lockdown Mode are not at risk.
- A security hobbyist using the handle 'matteyeux' demonstrated successfully hacking an iPad mini on iOS 18 with the leaked sample.
Connected Companies & Entities
5 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Darksword Exploit Kit Leaked, Puts Millions of iPhones at Risk
A modified version of the Darksword exploit kit has been published publicly on GitHub, lowering the technical barrier for large-scale attacks against iPhones and iPads. Security researchers uncovered a related hacking campaign in mid‑March 2026 that could target hundreds of millions of devices still running older iOS versions. The leaked package is composed of HTML and JavaScript files and includes code comments explaining exploit behavior and data exfiltration. Apple says devices running the latest updates (iOS 26.4/iPadOS 26) are protected and has issued emergency fixes for older models; users are advised to update or enable Lockdown Mode for extra protection.
Government Hacking Tools Now in Criminal Hands: Coruna
Security researchers have identified a suite of iPhone hacking tools called Coruna that appears to have moved from a government customer into criminal hands. Google first detected Coruna in February 2025 during a surveillance vendor’s attempt to deploy spyware for a government client, later observing the same kit used in a Russian campaign against Ukrainian users and by a financially motivated hacker in China. iVerify reverse-engineered the tools and linked them to the U.S. government based on similarities to previously attributed tooling. Coruna can chain 23 vulnerabilities to compromise iPhones via watering-hole/malicious-link attacks and affects devices running iOS 13 through 17.2.1. The case highlights risks from leaked government exploits and a growing market for “secondhand” exploits.
Coruna: The Global iPhone-Hacking Toolkit Exposed
TechCrunch reports that a sophisticated iPhone-hacking toolkit called “Coruna,” discovered by Google in 2025, was used in global attacks against targets in Ukraine, China and elsewhere. Independent analysis by mobile-security researchers at iVerify and anonymous former employees indicates parts of Coruna likely originated in Trenchant, the offensive cyber/surveillance division of U.S. military contractor L3Harris, which sells tools to U.S. and Five Eyes customers. Coruna’s components were reused across operations: Google tied two shared exploits (Photon and Gallium) to Operation Triangulation, while U.S. prosecutors say a former Trenchant general manager, Peter Williams, sold multiple Trenchant tools to the Russian broker Operation Zero for $1.3 million; Williams was recently sentenced to seven years. Coruna targeted iPhones running iOS 13 through 17.2.1 and appears to have migrated from government-to-state actors and then to financially motivated cybercriminals.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
