Roussille Benoît
Benoît is a cybersecurity analyst at EP-CERT, the European Parliament's computer emergency response team. He specialises in malware analysis, reverse engineering, and threat intelligence, with hands-on experience across the full defensive security stack. Curious by nature and craving for challenges, he is a regular CTF competitor ranking in the global top 100 of Flare-On for several consecutive years.
Session
March 2026 marked a turning point in the iOS threat landscape. Coruna and DarkSword became the first widely observed mass-exploitation campaigns targeting iOS devices at scale : a shared exploit kit used by multiple threat actors, shattering the assumption that iOS exploitation would remain the exclusive domain of nation-state tools like Pegasus or Predator.
This talk dissects Coruna (a campaign targeting cryptocurrency communities) following its full chain from browser fingerprinting and memory primitives through PAC bypass, code execution, privilege escalation, and implant delivery. Beyond the technical analysis, it offers an honest account of the analyst's journey: a low-cost observation setup using mitmproxy and a Raspberry Pi, the forensic artifacts that made the analysis possible, and a frank discussion of where LLM-assisted analysis accelerates work and where it produces dangerously confident wrong answers.
The talk also covers practical detection and infrastructure tracking using tools like Censys and URLScan.io.