Coruna iOS Exploit Kit — Government-Grade 23-Exploit Arsenal Proliferates from Surveillance Vendor to Russian Espionage and Chinese Cybercriminals Targeting 42K+ Devices — Threadlinqs Intelligence
As of 2026-05-30, Coruna iOS Exploit Kit — Government-Grade 23-Exploit Arsenal Proliferates from Surveillance Vendor to Russian Espionage and Chinese Cybercriminals Targeting 42K+ Devices is a critical-severity zero day threat attributed to L3Harris Trenchant (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0174 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: ZERO_DAY
Attribution: L3Harris Trenchant · Russia · ESPIONAGE
Google Threat Intelligence Group and iVerify disclosed Coruna, a sophisticated iOS exploit kit containing 5 full exploit chains and 23 individual exploits targeting iOS 13.0 through 17.2.1. The kit
Google Threat Intelligence Group (TAG) and iVerify published coordinated research on March 3, 2026 documenting Coruna, an exceptionally sophisticated iOS exploit kit containing 5 complete exploit chains and 23 individual exploits spanning iOS 13.0 (September 2019) through iOS 17.2.1 (December 2023). The research represents one of the most significant documented cases of government-grade exploit proliferation from surveillance vendors to both state-sponsored espionage groups and financially motivated cybercriminals.
Coruna chains multiple WebKit memory handling vulnerabilities for initial remote code execution, followed by sandbox escape and kernel exploitation to achieve full device compromise. The kit exploits at least six confirmed CVEs: CVE-2024-23222 (WebKit type confusion, CVSS 8.8, CISA KEV), CVE-2022-48503 (WebKit bounds check bypass, CVSS 8.8, CISA KEV as of October 2025), CVE-2023-43000 (WebKit use-after-free leading to memory corruption), CVE-2023-38606 (kernel state modification, actively exploited in Operation Triangulation), CVE-2023-32434 (kernel integer overflow enabling arbitrary code execution with kernel privileges, actively exploited in Operation Triangulation), and CVE-2023-32409 (WebKit sandbox escape, CVSS 8.6, actively exploited). Additional exploits within the kit lack CVE assignments but employ non-public exploitation techniques and mitigation bypasses.
iVerify's analysis linked Coruna's foundations to the same tooling used in Operation Triangulation, the sophisticated iOS surveillance campaign that Kaspersky discovered in 2023 targeting its own employees. Russian authorities attributed Operation Triangulation to U.S. intelligence services. CyberScoop reported that Coruna code contained comments suggesting U.S. government origin, and security researchers described the code as 'superb' with 'elegant' writing — hallmarks of well-resourced development teams.
The kit's attack methodology begins with hidden JavaScript on malicious websites that performs device reconnaissance, checking device model, iOS version, and security settings before selecting the appropriate exploit chain. Critically, Coruna detects and aborts execution when encountering Apple's Lockdown Mode or private browsing mode, demonstrating awareness of iOS security hardening features.
Google TAG documented three distinct deployment campaigns representing the kit's proliferation trajectory:
1. February 2025 — A commercial surveillance vendor customer deployed Coruna for targeted surveillance operations. The specific vendor and targets remain unnamed.
2. July 2025 — A suspected Russian espionage group deployed Coruna in watering hole attacks against Ukrainian websites, leveraging the ongoing Russia-Ukraine conflict for intelligence collection.
3. December 2025 — Chinese financially motivated cybercriminals deployed Coruna via fake gambling and cryptocurrency websites, achieving mass-scale infection of over 42,000 devices. iVerify's Chief Product Officer Spencer Parker termed this the first 'mass-scale attack on iOS' using government-grade exploit capabilities.
Payloads observed in the financially motivated campaign focused on cryptocurrency theft. The malicious stager binary could decode QR codes from disk images, search for keywords including 'backup phrase' and 'bank account', and exfiltrate cryptocurrency wallet data targeting applications including Metamask and BitKeep.
The Coruna kit is not effective against current iOS versions. Apple's security updates have addressed all known CVEs exploited by the kit. Lockdown Mode and private browsing both trigger evasion checks that prevent execution, making these effective defensive measures for at-risk users.
This case demonstrates the accelerating trickle-down of government-grade offensive cyber capabilities into the broader threat landscape, where exploit kits developed at enormous cost by nation-state programs or their surveillance vendor proxies eventually reach criminal actors who d
Weaknesses (CWE)
CWE-843, CWE-119, CWE-416, CWE-190
Target sectors: government, defense, financial, technology, media, cryptocurrency
Target regions: Ukraine, China, Global, Eastern Europe
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ZERO_DAY, CRITICAL, threat intelligence, cybersecurity, CVE-2024-23222, CVE-2022-48503, CVE-2023-43000, CVE-2023-38606, CVE-2023-32434, CVE-2023-32409, T1583.001, T1587.004, T1588.005, T1189, T1190, T1203, T1059.007, T1037, T1068, T1211