Hack.lu 2026

Coruna: a journey in a iOS analyst life studying the anatomy of an exploit kit

March 2026 marked a turning point in the iOS threat landscape. Coruna and DarkSword became the first widely observed mass-exploitation campaigns targeting iOS devices at scale : a shared exploit kit used by multiple threat actors, shattering the assumption that iOS exploitation would remain the exclusive domain of nation-state tools like Pegasus or Predator.
This talk dissects Coruna (a campaign targeting cryptocurrency communities) following its full chain from browser fingerprinting and memory primitives through PAC bypass, code execution, privilege escalation, and implant delivery. Beyond the technical analysis, it offers an honest account of the analyst's journey: a low-cost observation setup using mitmproxy and a Raspberry Pi, the forensic artifacts that made the analysis possible, and a frank discussion of where LLM-assisted analysis accelerates work and where it produces dangerously confident wrong answers.
The talk also covers practical detection and infrastructure tracking using tools like Censys and URLScan.io.


Coruna: a journey in a iOS analyst life studying the anatomy of an exploit kit

Introduction

  • Quick look at the iOS threat landscape
    • First public report in 2021 (Amnesty)
    • Usually targeted groups by expensive tools (Pegassus, Predator, Candiru...)
  • Coruna / Dark Sword are game changers (March 2026)
    • First widely observed mass exploitation (widely opened)
      • against crypto communities: Coruna
      • against Ukraine: DarkSword
    • Same exploit kit used by several TA from several regions
  • Focus of the presentation: Coruna
    • Very well designed
    • Wide spread of iOS/iPadOS versions supported
    • Interesting to confirm the methodology
    • but also ...
    • obfuscated vs clear text with comments
    • contains binary payloads vs only javascripts
    • where is the fun in darksword (clear text javascripts only with comments)?

Observing the attack in the wild

  1. Why not infecting ourselves a device?
  2. Start with a small setup with a PI + mitmproxy + tcpdump
    • provide us a way to observe exploitation
    • allow to generate artefacts (sysdiagnose and co) and correlate with our actions
  3. That was not really required: wget to the rescue with a bit of javascript reversing (LLM for the win in this case).

What do we need?

  • observing DNS traffic: requires to block DNS-over-HTTPs to force using plain DNS and our own resolver
  • observing HTTPS traffic: MITMPROXY + profile added to the device with self-signed master key
    • does not work when SSL pinning is in place (usually Apple & Google services among others)

Reverse

Stucture of the Coruna malware (high level):

  • fingerprinting of browser and getting arbitrary read-write in memory
  • identifying platform and PAC bypass
  • getting code execution
  • to infinity and beyond: shellcode --> privilege escalation --> implant

One more thing moment (on LLMs):

  • LLMs: a facilitator but pay attention to pitfall and wrong conclusions
  • Remember that LLM is all about statistics and probability. The more context you'll give the higher the chance you'll get an output that is usefull. Just feeding whole obfuscated javascript files can yield to completely wrong assessments like the one below:
    <img alt="" src="https://hdoc.csirt-tooling.org/uploads/13a028b2-040a-4466-a7cc-c99224209e79.png" />

Detection

  • network based IOC (require network visibility)
  • sysdiagnose (require to acquire the data close to the infected - max 2 days)

Tracking Coruna

  • Show how to track exploit kit with tools like Censys, URLSCAN.io...

Sharing knowledge in trusted groups

  • We have skills and knowledge within the cyber community and especially the EUIs
  • We advocate the need to share knowledge and howtos to defeat this type of attacks
  • Similar initiatives in the industry already exist: pall mall process

Conclusion

  • Mobile device are an essential tools
  • They are targeted like any other device and threat landscape is evolving rapidly
  • There is a need to be ready
    • we need to research the threat landscape
    • we need to build our tools
    • we need to build the knowledge on how to analyse
Roussille Benoît

Benoît is a cybersecurity analyst at EP-CERT, the European Parliament's computer emergency response team. He specialises in malware analysis, reverse engineering, and threat intelligence, with hands-on experience across the full defensive security stack. Curious by nature and craving for challenges, he is a regular CTF competitor ranking in the global top 100 of Flare-On for several consecutive years.

David Durvaux

Incident responder for more than a decade, I'm now working for the European Commission since 2015. I'm currently in charge of the "Situational Awareness, Threat Intelligence and Malware Analysis" in the European Commission Internal CERT (EC Cybersecurity Operation Centre).