Security researchers from the Google Threat Intelligence Group (GTIG) have uncovered “Coruna,” a highly sophisticated iOS exploit kit responsible for compromising thousands of iPhones.
Targeting iOS versions 13.0 through 17.2.1, the framework contains five complete exploit chains leveraging a staggering 23 vulnerabilities.
What began as a tool for a commercial surveillance vendor in early 2025 quickly proliferated into the hands of multiple global threat actors, highlighting a thriving secondary market for zero-day exploits.
Global Campaigns and Payload Analysis
The Coruna exploit kit’s timeline reveals a disturbing trend of advanced capabilities cascading to different cybercriminal factions.

First observed in February 2025 by a surveillance vendor’s customer, the framework was later adopted in summer 2025 by UNC6353, a suspected Russian espionage group.
UNC6353 deployed Coruna in watering-hole attacks against Ukrainian users via compromised local websites.

By late 2025, a financially motivated Chinese threat actor, UNC6691, launched broad-scale global campaigns using fake cryptocurrency exchanges, such as WEEX, to infect victims, as reported by Google Threat Intelligence Group (GTIG).
The final stage of the attack delivers a sophisticated stager binary named PlasmaLoader (tracked as PLASMAGRID), which injects into the iOS powerd root daemon. Unlike traditional spyware, PlasmaLoader focuses strictly on financial theft.
It scans Apple Memos for BIP39 backup phrases and deploys specialized modules to exfiltrate data from popular cryptocurrency wallets like MetaMask and Trust Wallet.

The malware communicates with command-and-control (C2) servers via HTTPS and features a Domain Generation Algorithm (DGA) fallback mechanism.
| IOC Type | Context & Technical Details |
|---|---|
| Malware Family | PlasmaLoader (PLASMAGRID stager binary) |
| Target Daemon | powerd (iOS root daemon), uses com.apple.assistd identifier |
| Malicious Domain | cdn.uacounter[.]com (Ukrainian watering hole iFrame) |
| Scam Domain | 3v5w1km5gv[.]xyz (Chinese fake cryptocurrency exchange) |
| File Artifacts | Custom 0xf00dbeef header, f6lib.js exfiltration module |
| Network Indicators | DGA seed “lazarus” generating predictable 15-character .xyz domains |
Vulnerability Mechanics and Mitigation
The Coruna framework is exceptionally well-engineered, utilizing JavaScript fingerprinting to deliver targeted WebKit remote code execution (RCE) exploits, followed by Pointer Authentication Code (PAC) bypasses and sandbox escapes.

Payloads are encrypted using ChaCha20 and delivered unencrypted only when specific device conditions are met. Notably, the exploit kit actively halts execution if it detects Apple’s Lockdown Mode or private browsing.
To protect against these sophisticated exploit chains, users are strongly advised to update to the latest iOS version immediately.
For individuals at high risk of targeted cyberattacks, enabling Apple’s Lockdown Mode provides a critical layer of defense that completely neutralizes the Coruna kit’s initial infection vectors.
Follow us on Google News, LinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.





