Find notable cyber news and cases, enriched with sources, timelines, and signals.
Campaign Exploitation Wave Security Patch Release Vulnerability

Coruna iPhone exploitation and Apple response

Updated 26.03.2026 13:07
Case score 63
Members 5 First seen 04.03.2026 15:28 Latest activity 26.03.2026 13:07

Overview

Coruna is being reused against **iPhone** users through watering-hole and lure-site delivery, with UNC6353 tied to compromised Ukrainian websites and UNC6691 tied to fake gambling and crypto pages. The kit fingerprints the device and iOS version before selecting an exploit path, and it will not run when **Lockdown Mode** or private browsing is enabled. The activity spans five exploit chains and 23 exploits across older iOS and iPadOS versions, including **CVE-2024-23222** and older WebKit and kernel flaws such as **CVE-2023-43010**. Apple has backported fixes for legacy devices and Google has blocked identified infrastructure, but available evidence still does not quantify the full reach of compromise.
Latest development Open development history 4 earlier developments Kaspersky links Coruna to Triangulation-era exploit code Kaspersky reported that the Coruna iOS exploit kit is an updated version of the kernel exploit code used in Operation Triangulation, with shared kernel exploitation framework elements, support for Apple's A17, M3, M3 Pro, and M3 Max processors, checks for iOS 17.2 and iOS 16.5 beta 4, and delivery of five full iOS exploit chains and 23 exploits that can lead to PlasmaLoader (aka PLASMAGRID) after a compromised Safari visit.
  1. Earlier development

    Coruna iOS exploit kit identified across Apple iPhone targets

    Google identified Coruna (aka CryptoWaters) as a new and powerful exploit kit targeting Apple iPhone models running iOS 13.0–17.2.1, and GTIG said it contained five full iOS exploit chains and 23 exploits built around device fingerprinting, WebKit RCE exploitation, and a PAC bypass. The same reporting also tied the framework to activity that circulated since February 2025, appeared on compromised Ukrainian websites in July 2025 through a hidden iFrame delivery path, and later surfaced on fake Chinese finance websites in December 2025 without geolocation constraints, while noting that the kit is not effective against the latest iOS.

  2. Earlier development

    Coruna iOS exploit kit linked to espionage and crypto theft

    Coruna is a previously undocumented iOS exploit kit with 23 exploits and five full exploit chains that affected iOS 13.0 through 17.2.1 and included CVE-2024-23222. GTIG first observed related activity in February 2025, later saw UNC6353 use the same framework in summer 2025 watering-hole attacks against iPhone users visiting compromised Ukrainian websites, and attributed late-2025 activity on fake Chinese gambling and crypto websites to UNC6691. Google added identified sites and domains to Safe Browsing and recommended updating iOS or enabling Lockdown Mode.

  3. Earlier development

    Apple backports Coruna-linked fixes to older iPhone and iPad models

    Apple backported the Coruna-linked CVE-2023-43010 fix to iOS 15.8.7, iPadOS 15.8.7, iOS 16.7.15, and iPadOS 16.7.15 for older iPhone and iPad models that cannot update to the latest iOS version, including iPhone 6s, iPhone 7, iPhone SE (1st generation), iPad Air 2, iPad mini (4th generation), iPod touch (7th generation), iPhone 8, iPhone 8 Plus, iPhone X, iPad 5th generation, iPad Pro 9.7-inch, and iPad Pro 12.9-inch 1st generation, while Google described Coruna as an exploit kit with 23 exploits across five chains targeting iPhone models on iOS 13.0–17.2.1.

  4. Earlier development

    Google details Coruna exploit kit scope

    Google said Coruna features 23 exploits across five chains designed to target iPhone models running iOS versions between 13.0 and 17.2.1, adding new scope detail to the WebKit-linked exploit kit associated with CVE-2023-43010.

Signals

Exploitation
Affected impact
CVEs/products
Geographic context
Remediation
Status
Threat context

Threat actor context

5 listed

Malware & tooling context

5 families · 5 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Campaign UNC6353 and UNC6691 Coruna iOS exploit campaign
Updated 04.03.2026 21:06 Lead Contribution 58
Campaign Active Patch Patch Available

The **Coruna** iOS exploit campaign spread through **watering-hole** and **fake finance/crypto** lures, extending reach from **iPhone users** to **crypto users**. **UNC6353** used the framework against compromised Ukrainian websites in **summer 2025**, and **UNC6691** later tied it to fake gambling and crypto sites in **late 2025**. The shift matters because the same exploit kit was reused across **espionage** and **financial theft** operations, broadening the risk to ordinary mobile users. The kit also selected exploit chains by device fingerprint and could stop when **Lockdown Mode** or private browsing was enabled.

Campaign Coruna watering-hole and fake-site exploitation campaign
Updated 26.03.2026 13:07 Scoring Support Contribution 3
Campaign Active

A suspected **Russia-aligned nation-state actor** is using **Coruna** in **watering-hole attacks in Ukraine** and a **mass exploitation campaign**, expanding the kit’s abuse beyond its original precision-espionage role. The operation steers users who visit compromised or lure websites through a browser-fingerprinting exploit chain that can select the right payload and deliver **PlasmaLoader (aka PLASMAGRID)**. That broadens risk for **unpatched Apple iPhone** users and shows how a once-targeted framework can be repurposed for wider abuse.

Exploitation Wave Coruna iOS mass exploitation wave
Updated 04.03.2026 15:28 Scoring Support Contribution 2
Exploitation Active Exploitation Patch Patch Available

The **Coruna** exploit kit marks the **first observed mass exploitation against iOS devices**, shifting risk from highly targeted spyware to **broad deployment** against **iPhone users**. It combines a **device-fingerprinting framework** with multiple iOS exploit chains to choose the right **WebKit RCE** path for each target. The development matters because it shows advanced mobile exploitation being reused at scale rather than confined to isolated surveillance operations.

Security Patch Release Apple security patch release for CVE-2023-43010
Updated 12.03.2026 11:58 Context
Exploitation Active Exploitation Urgency High Patch Patch Available

**Apple** backported **Coruna-linked WebKit fixes** to **older iOS and iPadOS devices**, reducing exposure on legacy hardware that cannot move to the latest release. The update extends protection for **CVE-2023-43010** and related flaws to iPhones and iPads left behind by newer versions. It matters because the flaw was used in an exploit kit that could process **malicious web content** and trigger **memory corruption**.

Vulnerability WebKit memory-corruption flaw actively exploited (CVE-2023-43010)
Updated 12.03.2026 11:58 Context
Exploitation Active Exploitation Patch Patch Available

Older **iPhone and iPad** devices received the **CVE-2023-43010** fix, extending protection against a **WebKit memory-corruption flaw** used in the **Coruna exploit kit**. The bug could be triggered by **maliciously crafted web content**, creating risk for browser-driven code execution on affected systems. The backport covers **iOS 15.8.7**, **iPadOS 15.8.7**, **iOS 16.7.15**, and **iPadOS 16.7.15** for devices that cannot move to newer releases. Apple said the issue had already been fixed in **iOS 17.2** on **December 11th, 2023**.