Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Coruna: Spy-grade iOS exploit kit powering financial crime
    Cybersecurity

    Coruna: Spy-grade iOS exploit kit powering financial crime

    adminBy adminMarch 4, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Coruna: Spy-grade iOS exploit kit powering financial crime
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A powerful iOS exploit kit has circulated among multiple threat actors over the past year, moving from a commercial surveillance operation to state-linked espionage campaigns and, ultimately, ended into the hands of financially motivated hackers, according to new research from Google’s Threat Intelligence Group (GTIG).

    “The exploit kit, named ‘Coruna’ by its developers, contained five full iOS exploit chains and a total of 23 exploits,” the analysts noted.

    The exploit list includes both CVE-tracked vulnerabilities and flaws that were never assigned CVE identifiers. (Though, as GTIG analysts noted, their ongoing investigation may result in a revision to CVE associations.)

    These vulnerabilities enable remote code execution and sandbox escapes via ordinary web content, exploiting flaws in WebKit’s memory handling and other browser subsystems.

    Among the CVEs with an exploit in this kit are:

    • CVE-2024-23222, a WebKit flaw exploited as a zero-day and patched in early 2024
    • CVE-2022-48503, a WebKit vulnerability added to CISA’s Known Exploited Vulnerabilities catalog in October 2025
    • CVE-2023-43000, fixed in Safari 16.6 and iOS 16.6 in November 2025
    • CVE-2023-38606 and CVE-2023-32434, used as zero-days as part of Operation Triangulation, discovered by Kaspersky in 2023
    • CVE-2023-32409, a WebKit flaw exploited as a zero-day

    Coruna iOS exploit kit unmasked

    The vulnerabilities leveraged by the exploit kit are mostly years-old issues, and most of them (possibly all) have been fixed since then.

    The exploit kit appears capable – with varying levels of reliability – of targeting iPhone models running iOS 13.0, released in September 2019, through iOS 17.2.1, released in December 2023.

    Google’s threat researchers first observed it being used in February 2025 by a customer of a surveillance company, then in July 2025 in watering hole attacks (by a suspected Russian espionage group) against Ukrainian websites, and finally in December 2025, via fake Chinese gambling and crypto websites.

    They managed to retrieve the complete exploit kit and all the obfuscated exploits. Then, due to the actor deploying a debug version of the exploit kit in one instance, they discovered the exploits’ code names and the name of the exploit kit.

    In addition to this, they found and analyzed the stager binary that the exploit kit was meant to deliver through the scam gambling sites: a malicious payload that could decode QR codes from images on disk, look for keywords like “backup phrase” or “bank account”, and run additional modules that can exfiltrate cryptocurrency wallets or sensitive information from a variety of crypto-wallet apps (Metamask, BitKeep, etc.)

    Coruna proliferation is still a mystery

    “The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits,” the researchers opined.

    “The exploits feature extensive documentation, including docstrings and comments authored in native English. The most advanced ones are using non-public exploitation techniques and mitigation bypasses.”

    How the kit came to be used by such a wide range of threat actors remains unclear, but seems to point to an active market for “second hand” zero-day exploits, according to the researchers.

    They confirmed that Coruna is not effective against the latest version of iOS and advised users to upgrade to it.

    If your iPhone is still on one of those versions and you can’t upgrade, putting your device in Lockdown Mode or using private browsing neutralizes it, as Coruna performs checks to avoid execution under such defensive configurations.

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    Coruna Crime exploit Financial iOS kit powering Spygrade
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous Article10 gates that decide whether you win the recommendation
    Next Article Grab the Amazon Fire TV Stick 4K Select at its cheapest price
    admin
    • Website

    Related Posts

    India APT Sloppy Lemming Targets Defense, Critical Infrastructure

    March 4, 2026

    Digital.ai expands post-build protection for Android and iOS applications

    March 4, 2026

    Hackers abuse OAuth error flows to spread malware

    March 4, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    India APT Sloppy Lemming Targets Defense, Critical Infrastructure

    March 4, 2026

    The MacBook Neo Isn’t the Only Low-Cost Mac Worth Buying

    March 4, 2026

    What They Are, and How to Choose the Right One

    March 4, 2026

    I stopped using Wi-Fi for my TV and I’m never going back

    March 4, 2026
    Categories
    • Blogging (33)
    • Cybersecurity (599)
    • Privacy & Online Earning (90)
    • SEO & Digital Marketing (377)
    • Tech Tools & Mobile / Apps (735)
    • WiFi / Internet & Networking (106)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    India APT Sloppy Lemming Targets Defense, Critical Infrastructure

    March 4, 2026

    The MacBook Neo Isn’t the Only Low-Cost Mac Worth Buying

    March 4, 2026

    What They Are, and How to Choose the Right One

    March 4, 2026
    Most Popular
    • India APT Sloppy Lemming Targets Defense, Critical Infrastructure
    • The MacBook Neo Isn’t the Only Low-Cost Mac Worth Buying
    • What They Are, and How to Choose the Right One
    • I stopped using Wi-Fi for my TV and I’m never going back
    • Digital.ai expands post-build protection for Android and iOS applications
    • How Jamie I.F. is Recovering From a Drop From $100K/Month to $3K/Month
    • Google Zero Is A Lie
    • Phone by Google 210.1.877624726-pixel APK Download by Google LLC
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.