Coruna is a sophisticated iOS exploitation framework and mobile hacking toolkit used to compromise Apple devices through web-based attack chains. It has been documented with five full exploit chains spanning 23 vulnerabilities and targeting iPhone and iPad devices running iOS versions from 13.0 through 17.2.1. The framework is modular and stages exploitation through Safari, selecting components based on device architecture, processor generation, and operating-system version before deploying loaders and a final implant. Analysis has linked part of its kernel exploitation logic to an updated form of the exploit framework used in Operation Triangulation, indicating an evolved and unified codebase rather than an ad hoc collection of exploits.
Coruna has been observed in targeted attacks by a customer of a commercial spyware vendor, in watering-hole campaigns against Ukrainian targets associated with UNC6353, and in broader financially motivated activity attributed to UNC6691. Reporting also describes proliferation beyond its original operators, with reuse by multiple actors including espionage and criminal operators. In some campaigns, Coruna was delivered through compromised or injected legitimate websites and watering-hole infrastructure that silently triggered exploitation when a vulnerable device visited the page. Researchers have also assessed some delivery frameworks seen in supply-chain and web-injection activity as Coruna or close derivatives.
Post-exploitation behavior includes deployment of an implant referred to as PLASMAGRID. Documented capabilities include command-and-control communications, kernel-memory access via launcher components, artifact cleanup, process injection, persistence, and activation of the implant after successful exploitation. In criminally adapted use, the implant has been associated with theft of cryptocurrency wallet seed phrases, demonstrating that the framework has been modified for financially motivated objectives in addition to espionage. Coruna has been characterized as spyware-grade tooling whose spread to secondary actors materially increased risk to users who remained on older, unpatched iOS releases.
Coruna is best understood as an exploit kit or exploitation framework rather than a conventional standalone malware family. Its significance lies in combining high-end browser, PAC-bypass, and kernel exploitation with modular post-exploitation components to silently install malware on vulnerable Apple mobile devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2023-43000: Another use-after-free vulnerability impacting macOS, iOS, and Safari, often exploited in exploit kits like Coruna for chaining attacks.
That domain redirects to the watering hole at utaq[.]cfww[.]shop/gooll/gooll.html, which embeds the Coruna exploit kit delivery framework analyzed in this report.
That domain redirects to the watering hole at utaq[.]cfww[.]shop/gooll/gooll.html, which embeds the Coruna exploit kit delivery framework analyzed in this report.
That domain redirects to the watering hole at utaq[.]cfww[.]shop/gooll/gooll.html, which embeds the Coruna exploit kit delivery framework analyzed in this report.
...анализ которой выявил внутренние имена эксплойтов и авторское название фреймворка — Coruna... В результате исследования выяснилось, что фреймворк эксплуатирует ряд ранее исправленных уязвимостей, в том числе CVE-2023-32434 и CVE-2023-38606.
...анализ которой выявил внутренние имена эксплойтов и авторское название фреймворка — Coruna... В результате исследования выяснилось, что фреймворк эксплуатирует ряд ранее исправленных уязвимостей, в том числе CVE-2023-32434 и CVE-2023-38606.
Coruna is one of those kits. Twenty-three exploits. Five full exploit chains. Coverage from iOS 13.0 through 17.2.1.
Coruna is one of those kits. Twenty-three exploits. Five full exploit chains. Coverage from iOS 13.0 through 17.2.1.
Coruna is one of those kits. Twenty-three exploits. Five full exploit chains. Coverage from iOS 13.0 through 17.2.1.
Coruna is one of those kits. Twenty-three exploits. Five full exploit chains. Coverage from iOS 13.0 through 17.2.1.
Coruna is one of those kits. Twenty-three exploits. Five full exploit chains. Coverage from iOS 13.0 through 17.2.1.
Coruna is one of those kits. Twenty-three exploits. Five full exploit chains. Coverage from iOS 13.0 through 17.2.1.
Last week, the iPhone maker also expanded patches for four security flaws (CVE-2023-43010, CVE-2023-43000, CVE-2023-41974, and CVE-2024-23222) that were weaponized as part of the Coruna exploit kit.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The story of Coruna and DarkSword has been already extensively reported on... A highly sophisticated exploit chain for iOS and other mobile operating systems... The original appearance of the malware kit was significant as it combined a set of exploits and zero-days to blast through iOS protections...
That domain redirects to the watering hole at utaq[.]cfww[.]shop/gooll/gooll.html, which embeds the Coruna exploit kit delivery framework analyzed in this report.
The proliferation of this single exploit chain across disparate threat actors mirrors the previously discovered Coruna iOS exploit kit. Notably, UNC6353, a suspected Russian espionage group previously observed using Coruna, has recently incorporated DarkSword into their watering hole campaigns.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2023-43000: Another use-after-free vulnerability impacting macOS, iOS, and Safari, often exploited in exploit kits like Coruna for chaining attacks.
The art-template npm package... was handed over to an unknown actor... The new controller almost immediately began weaponizing the package... pkg:npm/art-template@4.13.5 and pkg:npm/art-template@4.13.6 both append a browser-side remote-script loader
Three distinct obfuscation layers are applied... UTF-16 Integer Packer... new Function(atob("..."))() Eval Chain... Per-String XOR Encoding... Integer Constant Obfuscation
Модуль запуска очищает артефакты эксплойтов, извлекает имя процесса для инъекции из файла конфигурации с магическим числом 0xDEADD00F, внедряет стейджер в целевой процесс, использует его для самозапуска, а затем активирует имплант.
Сначала загруженный файл расшифровывается с помощью потокового шифра ChaCha20. На выходе получается контейнер с магическим числом 0xBEDF00D, содержащий сжатые при помощи LZMA данные.
Safari Эксплуатация начинается со стейджера, который собирает цифровой отпечаток браузера, после чего выбирает и запускает соответствующие эксплойты...
First, the whole system seems to be based on the popular NexusC2 framework for setting up Command-and-Control infrastructure.
They infect devices when the user simply visits a compromised legitimate site, use a chain of vulnerabilities to escape the browser sandbox, and silently exfiltrate messages, calls, location, browser history, Wi-Fi passwords, health data, notes and crypto wallets.
244 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
65 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated mobile exploit kit / malware platform targeting iOS and other mobile operating systems, combining multiple exploits and zero-days to bypass iOS protections and operated through a dashboard-backed C2 infrastructure.
Coruna is referenced as an iOS infection affecting a user who remained on iOS 16 after skipping updates, illustrating the security risk of delayed patch adoption.
An iOS exploit kit delivery framework used in a watering-hole campaign delivered via a compromised npm package. It fingerprints Safari/WebKit on iOS, performs anti-bot checks, beacons device data to C2, selects version-specific payload modules, and appears to stage browser exploits for iOS 11.0 through 17.2 while rejecting 17.3+ and non-target platforms.
Recently leaked exploit kit referenced as part of public exploit chains against modern iOS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.