Coruna Exploit Framework — Updated Operation Triangulation iOS Exploit Kit (CVE-2023-32434, CVE-2023-38606) — Threadlinqs Intelligence
As of 2026-05-30, Coruna Exploit Framework — Updated Operation Triangulation iOS Exploit Kit (CVE-2023-32434, CVE-2023-38606) is a critical-severity zero day threat attributed to Operation Triangulation Operator (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 26 indicators of compromise.
Threat ID: TL-2026-0286 · Severity: CRITICAL · CVSS: 8.8 · Status: ACTIVE · Category: ZERO_DAY
Attribution: Operation Triangulation Operator · Russia · ESPIONAGE
Kaspersky GReAT reveals the Coruna exploit framework, an updated version of the iOS exploit kit used in Operation Triangulation. The framework contains five kernel exploits — updated versions of
The Coruna exploit framework is a sophisticated, modular iOS exploitation platform revealed by Kaspersky's Global Research and Analysis Team (GReAT) on March 26, 2026. It represents an evolution of the exploit chain originally discovered during the Operation Triangulation investigation, which targeted iOS devices through zero-click iMessage exploitation beginning as early as 2019.
Coruna packages five kernel exploits into a single framework with architecture-aware payload selection. Two of these exploits are updated versions of the CVE-2023-32434 (integer overflow in XNU memory mapping syscalls) and CVE-2023-38606 (undocumented hardware MMIO register abuse for kernel memory protection bypass) vulnerabilities previously documented in Operation Triangulation. The remaining four kernel exploits are previously unobserved and target a range of iOS versions from pre-14.0 beta 7 through pre-17.2.
The attack chain begins with a Safari stager component that fingerprints the target browser and selects appropriate remote code execution (RCE) and Pointer Authentication Code (PAC) exploits based on the browser version. An encrypted component manifest is then downloaded, containing information about all available exploit packages. Multi-stage decryption uses ChaCha20 stream cipher with 256-bit keys followed by LZMA decompression. The framework uses distinctive magic numbers: 0xBEDF00D for LZMA-compressed containers, 0xF00DBEEF for file storage containers, 0x12345678 for package information format, and 0xDEADD00F for launcher configuration.
Package selection is architecture and version-specific: package IDs 0xF2/0xF3 correspond to ARM64/ARM64E kernel exploits, 0xA2/0xA3 to Mach-O loaders, and the range 0xF3300000-0xF3900000 to iOS version-specific exploit variants. File IDs within packages include 0x10000 (implant), 0x50000 (Mach-O loader), 0x70000 (component list), 0x90000 (kernel exploit), and 0xA0000 (logs cleaner).
The CVE-2023-38606 exploit is particularly notable as it abuses undocumented Apple hardware MMIO registers at addresses 0x206040000, 0x206140000, and 0x206150000 on A12-A16 Bionic SoCs to bypass the Page Protection Layer (PPL). These registers interact with the GPU coprocessor subsystem and were not documented in any public specification, device tree firmware, or source code — raising significant questions about how the attackers discovered them.
Post-exploitation capabilities include process injection via a Mach-O loader, a launcher component for orchestrating implant deployment, kernel memory read/write through exploit-created kernel objects, and an artifact removal component that cleans logs and forensic traces. The framework supports configurable target process names for injection.
Delivery has been observed through three distinct channels: watering-hole attacks targeting Ukrainian entities, financially motivated attacks in China, and distribution through an unnamed surveillance vendor's customer operations. Google Threat Intelligence and iVerify published related reports on March 4, 2026, followed by Kaspersky's full framework analysis on March 26, 2026.
The original Operation Triangulation campaign used an 11,000-line obfuscated JavaScript exploit delivered via zero-click iMessage attachments, exploiting CVE-2023-41990 (TrueType font instruction vulnerability), CVE-2023-32434, CVE-2023-38606, and CVE-2023-32435 in sequence. The Coruna framework represents a significant evolution — packaging updated exploits with broader chip support (A13 through A17, M3/M3 Pro/M3 Max), multi-architecture awareness, and encrypted modular delivery.
Weaknesses (CWE)
CWE-190, CWE-269, CWE-119, CWE-787
Target sectors: government, defense, technology, telecommunications, research, financial, critical-infrastructure
Target regions: Eastern Europe, Ukraine, China, Global
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 26 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ZERO_DAY, CRITICAL, threat intelligence, cybersecurity, CVE-2023-32434, CVE-2023-38606, CVE-2023-41990, CVE-2023-32435, T1189, T1190, T1203, T1106, T1547, T1068, T1027, T1070, T1055, T1553