Tuesday, September 8, 2026

Thousands of iPhones Compromised in Massive Hack via Coruna Exploit Kit with 23 Vulnerabilities

Security researchers from the Google Threat Intelligence Group (GTIG) have uncovered “Coruna,” a highly sophisticated iOS exploit kit responsible for compromising thousands of iPhones.

Targeting iOS versions 13.0 through 17.2.1, the framework contains five complete exploit chains leveraging a staggering 23 vulnerabilities.

What began as a tool for a commercial surveillance vendor in early 2025 quickly proliferated into the hands of multiple global threat actors, highlighting a thriving secondary market for zero-day exploits.

Global Campaigns and Payload Analysis

The Coruna exploit kit’s timeline reveals a disturbing trend of advanced capabilities cascading to different cybercriminal factions.

Coruna iOS exploit kit timeline (Source: Google)
Coruna iOS exploit kit timeline (Source: Google)

First observed in February 2025 by a surveillance vendor’s customer, the framework was later adopted in summer 2025 by UNC6353, a suspected Russian espionage group.

UNC6353 deployed Coruna in watering-hole attacks against Ukrainian users via compromised local websites.

Deobfuscated JavaScript of the Coruna exploit kit (Source: Google)
Deobfuscated JavaScript of the Coruna exploit kit (Source: Google)

By late 2025, a financially motivated Chinese threat actor, UNC6691, launched broad-scale global campaigns using fake cryptocurrency exchanges, such as WEEX, to infect victims, as reported by Google Threat Intelligence Group (GTIG).

The final stage of the attack delivers a sophisticated stager binary named PlasmaLoader (tracked as PLASMAGRID), which injects into the iOS powerd root daemon. Unlike traditional spyware, PlasmaLoader focuses strictly on financial theft.

It scans Apple Memos for BIP39 backup phrases and deploys specialized modules to exfiltrate data from popular cryptocurrency wallets like MetaMask and Trust Wallet.

Pop-up on a fake cryptocurrency exchange website trying to drive users to the exploits (Source: Google)
Pop-up on a fake cryptocurrency exchange website trying to drive users to the exploits (Source: Google)

The malware communicates with command-and-control (C2) servers via HTTPS and features a Domain Generation Algorithm (DGA) fallback mechanism.

IOC TypeContext & Technical Details
Malware FamilyPlasmaLoader (PLASMAGRID stager binary)
Target Daemonpowerd (iOS root daemon), uses com.apple.assistd identifier
Malicious Domaincdn.uacounter[.]com (Ukrainian watering hole iFrame)
Scam Domain3v5w1km5gv[.]xyz (Chinese fake cryptocurrency exchange)
File ArtifactsCustom 0xf00dbeef header, f6lib.js exfiltration module
Network IndicatorsDGA seed “lazarus” generating predictable 15-character .xyz domains

Vulnerability Mechanics and Mitigation

The Coruna framework is exceptionally well-engineered, utilizing JavaScript fingerprinting to deliver targeted WebKit remote code execution (RCE) exploits, followed by Pointer Authentication Code (PAC) bypasses and sandbox escapes.

 Coruna exploit chain delivered on iOS 15.8.5 (Source: Google)
 Coruna exploit chain delivered on iOS 15.8.5 (Source: Google)

Payloads are encrypted using ChaCha20 and delivered unencrypted only when specific device conditions are met. Notably, the exploit kit actively halts execution if it detects Apple’s Lockdown Mode or private browsing.

CVE IDCVSS ScoreDescriptionCWE
CVE-2024-232228.8 â€‹WebKit RCE vulnerability (Codename: cassowary) allowing arbitrary code execution via type confusion â€‹.Type Confusion â€‹
CVE-2023-43000High â€‹WebKit RCE vulnerability (Codename: terrorbird) causing memory corruption when processing web content â€‹.Memory Corruption â€‹
CVE-2023-324098.6 â€‹WebKit Sandbox Escape (Codename: IronLoader) allowing a remote attacker to break out of the Web Content sandbox â€‹.Out-of-Bounds â€‹

To protect against these sophisticated exploit chains, users are strongly advised to update to the latest iOS version immediately.

For individuals at high risk of targeted cyberattacks, enabling Apple’s Lockdown Mode provides a critical layer of defense that completely neutralizes the Coruna kit’s initial infection vectors.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Claude Mythos Executes End-to-End Intrusion From Initial Access to Full Domain Compromise

Anthropic’s Claude Mythos Preview has demonstrated the ability to...

WhatsApp Testing Guest Calls for People Without a WhatsApp Account

WhatsApp is developing a guest-call feature that would let...

The 12 Best Antivirus (Endpoint Protection) Software for Business, Compared and Priced

Best value overall: Microsoft Defender for Endpoint — if...

The 12 Best Managed Firewall Services, Compared and Priced

Best value overall: Fortinet. Delivered directly and through the...

Related Articles

Recent News