iVerify

Mateusz Krzywicki

Mateusz Krzywicki

2026

Core Meltdown: Inside Coruna and DarkSword

Coruna and DarkSword shocked the world with their reach, each framework deployed individually as robust capabilities with the means to exploit millions of iPhones. Although initially tied to financially-motivated adversaries, subsequent analysis and threat intelligence reports clearly highlighted the frameworks' use as sophisticated extensions of threat actors' tactical repertoire.

Threat analysts noted the marked shift away from tailored spyware deployment against targeted individuals; Coruna and DarkSword were both deployed as part of watering hole attacks, a specific form of evil with no regard for who was on the receiving end. These infections are not enabled by traditional forms of targeting as enabled by commercial spyware vendors. Both exploit frameworks can be triggered with the use of simple `iframe` elements, surgically placed and served up inside of popular website content.

These exploit frameworks, when combined, support the exploitation of iOS versions 13 through 18.7. Both frameworks were leaked after the reports broke, and they have since proliferated. It is our standing opinion that these frameworks are here to stay and they will continue to evolve over time.

This talk aims to provide the audience with a comparison of deployments for both Coruna and DarkSword. This talk will also explore possible evolutions of their deployment in the near future. We will highlight the necessity for increased visibility into mobile devices and increased demand for mobile-specialized defensive talent within the industry. The talk will remain centered around the forensic implications of a live infection, how each spyware agent navigates the targeted iOS device, and how these behaviors improve our ability to detect a broader spectrum of commercialized and proliferating spyware. We will also take the time to discuss the identification of a threat actor deploying these capabilities—jointly—within the same campaign, to maximize coverage of iOS devices. 


About Mateusz Krzywicki

Mateusz Krzywicki is Vice President of Threat Research at iVerify and a security researcher with more than 15 years of experience in vulnerability research, reverse engineering, and exploit development. Throughout his career, he has held senior security roles at Apple, Amazon, Microsoft, and ESET, where he secured widely deployed software and hardware platforms against sophisticated attacks. His research focuses on browser security, operating system internals, sandbox escapes, IPC mechanisms, kernel security, and advanced fuzzing techniques. 

He has discovered and analyzed numerous high-impact vulnerabilities, contributed to memory-safety mitigations, and developed specialized tooling for vulnerability discovery, root-cause analysis, and exploit detection. Mateusz is passionate about uncovering new attack surfaces, advancing defensive technologies, and exploring the evolving intersection of software security and offensive research. He regularly shares technical research with the security community.