
Kevin Hoganson

2026
Core Meltdown: Inside Coruna and DarkSword
Coruna and DarkSword shocked the world with their reach, each framework deployed individually as robust capabilities with the means to exploit millions of iPhones. Although initially tied to financially-motivated adversaries, subsequent analysis and threat intelligence reports clearly highlighted the frameworks' use as sophisticated extensions of threat actors' tactical repertoire.
Threat analysts noted the marked shift away from tailored spyware deployment against targeted individuals; Coruna and DarkSword were both deployed as part of watering hole attacks, a specific form of evil with no regard for who was on the receiving end. These infections are not enabled by traditional forms of targeting as enabled by commercial spyware vendors. Both exploit frameworks can be triggered with the use of simple `iframe` elements, surgically placed and served up inside of popular website content.
These exploit frameworks, when combined, support the exploitation of iOS versions 13 through 18.7. Both frameworks were leaked after the reports broke, and they have since proliferated. It is our standing opinion that these frameworks are here to stay and they will continue to evolve over time.
 This talk aims to provide the audience with a comparison of deployments for both Coruna and DarkSword. This talk will also explore possible evolutions of their deployment in the near future. We will highlight the necessity for increased visibility into mobile devices and increased demand for mobile-specialized defensive talent within the industry. The talk will remain centered around the forensic implications of a live infection, how each spyware agent navigates the targeted iOS device, and how these behaviors improve our ability to detect a broader spectrum of commercialized and proliferating spyware. We will also take the time to discuss the identification of a threat actor deploying these capabilities—jointly—within the same campaign, to maximize coverage of iOS devices.Â
About Kevin Hoganson
Kevin Hoganson serves as a Senior Threat Hunter at iVerify, where he leverages a broad skill set across cyber threat intelligence, digital forensics, and incident response. Self-described as a "jack of all trades," Kevin comes from a predominantly offensive background shaped by years of experience in both government service and the broader defense industry. Kevin has enjoyed time as a consultant within the unique domains of cyber operations and cyber threat intelligence, having supported large analytic efforts with a practiced approach to reverse engineering complex systems and malware samples proliferating in the wild.
