INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Apple patches Coruna exploit kit flaws in iOS 15.0

| 2026-03-12 17:49 CRITICAL HIGH
Executive Summary AI-generated
The Coruna exploit kit has been quietly spreading its influence across the globe, targeting highly targeted attacks on Ukrainian users by a suspected Russian espionage group. Initially observed in watering hole attacks against Apple iPhone models running iOS version 13.0 to 17.2.1, the threat actor used fake finance and crypto-related websites to deliver the exploit kit. The framework was later seen being deployed again in summer, this time targeting iPhone users visiting compromised Ukrainian websites for ecommerce, industrial equipment and retail tools, and local services. As of March 12, Apple had patched vulnerabilities used in the Coruna exploit kit for older mobile devices that can no longer be updated to the latest iOS version. However, newer iOS versions have already been shipped with patches associated with the exploit, providing a temporary reprieve from the threat. The incident highlights the ongoing cat-and-mouse game between cybercriminals and tech companies, as they seek to stay one step ahead of each other in their pursuit of intellectual property theft and espionage.
Technical Mitigations AI-generated
* Use a reputable antivirus software and keep it up to date, as many malwarebytes solutions can help protect against spyware-grade Coruna iOS exploit kits. * Regularly update your iPhone or iPad to the latest iOS version (if available) and enable Automatic Updates if not already set up. This will ensure you have the latest security patches and fixes. * Be cautious when using public Wi-Fi networks, as they may be vulnerable to man-in-the-middle attacks that could compromise your device's security. * Use a VPN (Virtual Private Network) when accessing sensitive information or making online transactions, as it can help protect against data breaches by encrypting your internet traffic.
Technical Observables
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Operation Triangulation OfOperation Triangulation OfOperation TriangulationOperation Triangulation CVE-2022-48503CVE-2022-48503 CVE-2023-43000CVE-2023-43000 CVE-2023-41974CVE-2023-41974 CVE-2020-27932CVE-2020-27932 CVE-2024-23222CVE-2024-23222 CVE-2023-38606CVE-2023-38606 CVE-2023-32434CVE-2023-32434
Target & Sectors
UA CN RU
financefinance governmentgovernment retailretail
Incident Timeline
September 2019
Threat actors used a Coruna exploit kit to target Apple iPhone models running iOS version 13.0 up to version 17.2.1, exploiting vulnerabilities in these versions of the operating system.
infrastructure Ios
general_metric 23 exploits
infrastructure 17.2.1
general_metric 13.0 iOS versions
infrastructure 13.0
organisation Google
June 2023
Threat actors used Kaspersky to discover iPhones on its network that had been compromised by Operation Triangulation.
campaign Operation Triangulation
organisation Kaspersky
organisation iPhones
July 2023
Threat actors exploited CVE-2023-43000 in older versions of iOS and iPadOS, which were patched by Apple.
infrastructure Ios
vulnerability CVE-2023-43000
infrastructure 16.6
infrastructure 16.6 iPadOS
December 2023
Threat actors used a Coruna exploit kit to target older iOS versions.
infrastructure Ios
infrastructure 13.0
infrastructure 17.2.1
general_metric 13.0 iOS versions
general_metric 23 exploits
organisation Google
infrastructure 16.6
infrastructure 17.2
organisation iPad
organisation WebKit
organisation CVE-2023-43000
organisation CVE-2023-41974
January 22, 2024
Threat actors exploited a vulnerability in older iOS versions to gain unauthorized access.
infrastructure Ios
organisation Apple
January 2024
Threat actors used a WebKit vulnerability, CVE-2024-23222, to target older versions of iOS and iPadOS.
infrastructure Ios
vulnerability CVE-2024-23222
February 2025
Threat actors used a Coruna exploit kit to target older iOS versions.
attribution Google Threat Intelligence Group
infrastructure Ios
industry Government
source_region China
2025-03-04
Threat actors used a T1059.007 JavaScript exploit kit to target older iOS versions on 2025-03-04.
infrastructure Ios
tactic T1059.007 - JavaScript
late 2025
Threat actors used a fake Chinese gambling and crypto website to distribute the Coruna exploit kit.
target_region China
summer 2025
Threat actors exploited vulnerabilities in older iOS versions to gain access to targeted Ukrainian websites.
target_region Ukraine
target_region Russian Federation
the end of 2025
Threat actors used a framework to target older iOS versions, hosting it on fake Chinese websites related to finance and cryptocurrency.
industry Finance
target_region China
July 2025
Threat actors exploited a Coruna exploit kit flaw in older iOS versions by using the same JavaScript framework on compromised Ukrainian websites.
target_region Ukraine
tactic T1059.007 - JavaScript
observable cdn.uacounter
November 11, 2025
Threat actors used a previously unknown exploit kit to target older iOS versions.
December 2025
Threat actors exploited a vulnerability in the T1059.007 JavaScript framework to target older versions of iOS in December 2025.
tactic T1059.007 - JavaScript
March 3, 2026
Threat actors used a previously unknown exploit in the Coruna vulnerability to target Apple iPhone models running iOS version 13.0 up to version 17.2.1 on March 3, 2026.
infrastructure Ios
infrastructure 13.0
infrastructure 17.2.1
general_metric 13.0 iOS versions
organisation Google
2026-03-12
The Coruna iOS exploit kit uses 23 exploits across five chains targeting iOS 13-17.2.1, including WebKit remote code execution and pointer authentication bypasses.
infrastructure Ios
infrastructure Android
organisation UNC6353
organisation Kaspersky
organisation Google
organisation iPhone
organisation iPad
organisation WebKit
organisation PlasmaLoader
organisation PlasmaGrid
organisation Safe Browsing
infrastructure 13.0
infrastructure 17.2.1
organisation Apple
organisation CryptoWaters
organisation CVE-2024-23222
organisation AES
organisation CVE-2020-27932
organisation CVE-2023-43000
organisation CVE-2022
organisation PAC
organisation iPhones
organisation Operation Triangulation
organisation National Security Agency
organisation CVE-2023-32434
organisation CVE-2023-38606
organisation Operation Triangulation Of
organisation Photon and Gallium
organisation FSB
organisation UNC6691
organisation Uniswap
organisation DGA
organisation iVerify
organisation Wired
organisation GTIG
organisation The Red Report 2026
organisation The Register
organisation Triangulation
organisation TLD
organisation DNS
Tactical Metrics
Metrics
infrastructure
​Ios
Affected Product
Metrics
infrastructure
​13.0
Software Version
Metrics
infrastructure
​17.2.1
Software Version
Metrics
infrastructure
​16.6
Software Version
Metrics
infrastructure
17
Ipados
Metrics
infrastructure
​17.2
Software Version
Metrics
infrastructure
​Android
Affected Product
Intelligence Sources