INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Triangulation Exploit Framework Linked to Triangulation Attacks

| 2026-03-26 19:12 CRITICAL HIGH
Executive Summary AI-generated
The Coruna iOS exploit kit is a highly capable and advanced framework that has been used to steal sensitive data from Apple devices. Developed by cybercriminals of a broader kind, this toolkit enables full-chain attacks to target iPhones running iOS 18.4–18.7 and has been observed in campaigns targeting countries such as Saudi Arabia, Turkey, Malaysia, and Ukraine. The Coruna exploit kit uses an updated version of the same kernel exploit seen in the 2023 Operation Triangulation campaign, suggesting a possible link between the two. This suggests that Coruna is not a mix of reused parts but a more advanced evolution of the same exploitation framework behind Operation Triangulation.
Technical Mitigations AI-generated
* Implement a patching mechanism for iOS versions prior to the targeted exploit's vulnerability (CVE-2023-32434 and CVE-2023-38606) to prevent exploitation. * Regularly update software components, including Safari and other browsers used by devices running Coruna exploits, to ensure they are patched against known vulnerabilities. * Use a secure coding practice that includes checking for compatibility with newer iOS versions (up to 17.2), CPU architectures, and firmware versions to improve the exploit's effectiveness and reduce the risk of detection. * Implement a dynamic analysis mechanism to detect and adapt to changes in the target environment, such as device type, CPU, and iOS version, to maximize the payload's effectiveness. * Consider implementing a sandboxing or isolation approach for devices running Coruna exploits to prevent lateral movement and minimize the attack's impact.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation TriangulationOperation Triangulation CVE-2023-32434CVE-2023-32434 CVE-2023-38606CVE-2023-38606
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
fall 2023
Threat actors used a newly discovered exploit in iOS 16.5 beta 4 to target devices running Triangulation iOS exploitation framework, which evolved from earlier versions including A17 and M3 processors.
infrastructure Ios
general_metric 16.5 beta
general_metric 4 beta
infrastructure 16.5
late 2023
Threat actors used undocumented features in Apple chips to bypass hardware-based security protections.
June 2023
Threat actors used a previously unknown exploit in the Triangulation iOS exploitation framework to target devices.
December 2023
Threat actors used a previously unknown exploit in the Triangulation iOS exploitation framework to target devices running December 2023 versions of iOS.
infrastructure Ios
February 2025
The exploit kit used in the Coruna incident targets iPhones running iOS 17.2 or newer, and its loader is updated to support recent Apple chips like A17 and M3.
infrastructure Ios
tactic T1059.007 - JavaScript
organisation Operation Triangulation
organisation CVE-2023-32434
organisation CVE-2023-38606
organisation Analysis
infrastructure 16.5
infrastructure 17.2
organisation CPU
organisation Apple
organisation XNU
organisation A17
organisation SecurityAffairs
2025-03-26
Threat actors used a previously unknown exploit in the Triangulation iOS framework to target devices.
target_region China
source_region Russian Federation
source_region Ukraine
organisation PlasmaLoader
late 2025
Threat actors used a new iOS exploit kit called DarkSword to target devices in late 2025.
infrastructure Ios
organisation DarkSword
March 4, 2026
Threat actors used a previously unknown exploit in the Triangulation iOS exploitation framework to target devices.
organisation iVerify
organisation Apple
Mar 26, 2026
Threat actors used a previously unknown exploit in the Triangulation iOS exploitation framework to target devices.
2026-03-26
The Coruna exploit reveals evolution of Triangulation iOS exploitation framework.
campaign Operation Triangulation
vulnerability CVE-2023-32434
organisation CVE-2023-38606
general_metric 38606 vulnerabilities
organisation UNC6353
organisation UNC6691
organisation iPhones
infrastructure Ios
organisation DarkSword
organisation APT
organisation CVE-2023
organisation Kaspersky
organisation Apple
infrastructure 16.5
infrastructure 17.2
organisation Package
organisation Kernel
organisation A13
organisation Triangulation
organisation Kaspersky Global Research and Analysis Team
organisation Kit Reuses 2023
organisation iVerify
organisation Google
infrastructure 13.0
infrastructure 17.2.1
infrastructure 13.0 iPhones
organisation PAC
organisation RCE
organisation Magic
organisation Entry[0].Status
organisation Entry[0].File
organisation File
organisation File ID
organisation CPU
organisation Observed File
organisation Launcher
organisation The Hacker News
organisation The Red Report 2026
organisation Triangulation and Coruna
organisation GitHub
organisation TechCrunch
Tactical Metrics
Metrics
infrastructure
​Ios
Affected Product
Metrics
infrastructure
​16.5
Software Version
Metrics
infrastructure
​17.2
Software Version
Metrics
infrastructure
​13.0
Software Version
Metrics
infrastructure
​17.2.1
Software Version
Metrics
infrastructure
13
Iphones
Intelligence Sources