Coruna iOS Exploit Kit — 23 Exploits Across 5 Chains Targeting iOS 13-17.2.1 (CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 + 20 More) — Threadlinqs Intelligence
As of 2026-05-30, Coruna iOS Exploit Kit — 23 Exploits Across 5 Chains Targeting iOS 13-17.2.1 (CVE-2021-30952, CVE-2023-41974, CVE-2023-43000 + 20 More) is a critical-severity vulnerability threat attributed to UNC6353 (Russia / China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-0186 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Attribution: UNC6353 · Russia / China · ESPIONAGE
Google Threat Intelligence Group (GTIG) identified Coruna, a commercial-grade iOS exploit kit containing 23 exploits across 5 full exploit chains targeting iOS 13.0 through 17.2.1. Initially deployed
Coruna is a sophisticated, modular iOS exploit kit first observed by Google's Threat Intelligence Group (GTIG) in February 2025, when researchers captured an iOS exploit chain used by a customer of a commercial surveillance vendor. The kit represents one of the most comprehensive iOS exploitation frameworks ever documented, containing 23 individual exploits organized into 5 full attack chains that collectively target every iOS version from 13.0 (September 2019) through 17.2.1 (December 2023).
The exploit kit combines WebKit memory corruption vulnerabilities for initial remote code execution, sandbox escape exploits, kernel privilege escalation, Pointer Authentication Code (PAC) bypasses, and Page Protection Layer (PPL) bypasses to achieve full device compromise. The individual exploit components carry internal codenames including buffout (CVE-2021-30952), Photon (CVE-2023-32434), Gallium (CVE-2023-38606), IronLoader (CVE-2023-32409), Parallax (CVE-2023-41974), terrorbird (CVE-2023-43000), and others. Notably, the Photon and Gallium components were previously linked to Operation Triangulation, the iOS espionage campaign revealed by Kaspersky in 2023.
The infection vector uses a JavaScript framework that fingerprints the target device, determines the appropriate exploit chain based on iOS version, loads a WebKit RCE exploit, executes a PAC bypass, and deploys the payload via a hidden iFrame. The framework includes evasion mechanisms — it terminates if Lockdown Mode is enabled and exits in private browsing mode. Payloads are encrypted using LZW compression combined with ChaCha20 encryption.
The final-stage payload is PlasmaLoader (tracked by GTIG as PLASMAGRID), a stager binary that uses the identifier com.apple.assistd and injects itself into powerd, a daemon running as root on iOS. PlasmaLoader is designed to decode QR codes from images, hook into 18+ cryptocurrency wallet applications (including MetaMask, Phantom, Exodus, BitKeep, TokenPocket, Uniswap, Base, Bitget Wallet), and scan Apple Notes for BIP39 seed phrases and keywords like 'backup phrase' or 'bank account'. Stolen data is encrypted with AES before exfiltration to hardcoded C2 servers.
The implant embeds a custom domain generation algorithm (DGA) using the string 'lazarus' as a seed to generate predictable 15-character domains with .xyz TLD as fallback C2 channels. Network indicators include anomalous HTTP headers 'sdkv' and 'x-ts' in C2 communications.
Proliferation occurred across three distinct phases. In February 2025, GTIG first observed the kit deployed by a surveillance vendor customer in highly targeted operations. By July 2025, the JavaScript framework appeared on cdn.uacounter[.]com in watering hole attacks targeting Ukrainian websites spanning industrial equipment, retail, and e-commerce sectors, attributed to UNC6353, a suspected Russian espionage group. The exploit was selectively triggered only for iPhone users in specific geographic regions. By December 2025, the complete kit was weaponized by UNC6691, a financially motivated Chinese threat actor, across a network of fraudulent cryptocurrency and financial websites (including fake WEEX exchange sites) with no geolocation filtering — marking the first observed mass exploitation campaign against iOS devices using spyware-grade exploit chains.
Code analysis revealed comments written in Chinese within the UNC6691 campaign modules, and evidence of large language model-generated content in some components. iVerify independently tracks this framework as CryptoWaters and has noted similarities to frameworks previously developed by threat actors affiliated with the U.S. government.
On March 5, 2026, CISA added three Coruna-exploited vulnerabilities to the Known Exploited Vulnerabilities catalog: CVE-2021-30952, CVE-2023-41974, and CVE-2023-43000, with a federal remediation deadline of March 26, 2026.
---
**Revalidated on 2026-03-12**
Since the original threat publication, the Coruna iOS exploit kit h
Weaknesses (CWE)
CWE-119, CWE-120, CWE-125, CWE-190, CWE-20, CWE-295, CWE-362, CWE-416, CWE-787, CWE-843
Target sectors: government, defense, financial, technology, cryptocurrency, retail, industrial, e-commerce, media, civil-society
Target regions: Ukraine, Eastern Europe, China, Southeast Asia, Global
Detections & IOCs
As of 2026-07-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2021-30952, CVE-2023-41974, CVE-2023-43000, CVE-2023-42917, CVE-2023-42916, CVE-2023-41993, CVE-2023-41991, CVE-2023-41990, CVE-2023-41064, CVE-2023-41061, T1189, T1190, T1203, T1106, T1554, T1068, T1055, T1036, T1027, T1497