BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2026//talk//P89X7V
BEGIN:VTIMEZONE
TZID:Europe/Luxembourg
BEGIN:DAYLIGHT
DTSTART:20251020T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Coruna: a journey in a iOS analyst life studying the anatomy of an
  exploit kit - Roussille Benoît\, David Durvaux
DTSTART;TZID=Europe/Luxembourg:20261020T173000
DTEND;TZID=Europe/Luxembourg:20261020T180000
DTSTAMP:20261009T054100Z
UID:pretalx-hack-lu-2026-P89X7V@pretalx.com
DESCRIPTION:March 2026 marked a turning point in the iOS threat landscape.
  Coruna and DarkSword became the first widely observed mass-exploitation c
 ampaigns targeting iOS devices at scale : a shared exploit kit used by mul
 tiple threat actors\, shattering the assumption that iOS exploitation woul
 d remain the exclusive domain of nation-state tools like Pegasus or Predat
 or.\nThis talk dissects Coruna (a campaign targeting cryptocurrency commun
 ities) following its full chain from browser fingerprinting and memory pri
 mitives through PAC bypass\, code execution\, privilege escalation\, and i
 mplant delivery. Beyond the technical analysis\, it offers an honest accou
 nt of the analyst's journey: a low-cost observation setup using mitmproxy 
 and a Raspberry Pi\, the forensic artifacts that made the analysis possibl
 e\, and a frank discussion of where LLM-assisted analysis accelerates work
  and where it produces dangerously confident wrong answers.\nThe talk also
  covers practical detection and infrastructure tracking using tools like C
 ensys and URLScan.io.
LOCATION:Europe
URL:https://pretalx.com/hack-lu-2026/talk/P89X7V/
END:VEVENT
END:VCALENDAR
