Google's Threat Intelligence Team and security firm iVerify have shared details about Coruna , an exploit kit that combines multiple vulnerabilities to target iPhones running older versions of iOS .

The Corona exploit kit leverages five full exploit chains iOS to compromise unpatched iPhones running iOS versions 13 through 17.2.1. It works by combining multiple vulnerabilities to progressively compromise the security layers of the devices.
See also: Google: Vulnerability in Qualcomm Android Component used by hackers
How does the Coruna exploit kit targeting iPhones work?
After visiting a malicious website, which uses hidden JavaScript to check the device model, system version, and other security settings, the attack can take multiple paths to bypass basic iOS protections, gain elevated privileges , and install malware that can collect data or download additional payloads.
One of the important elements of the exploit is that it checks if the device has Lockdown Mode, and if so, it aborts the process. It also aborts if the user is in private browsing mode.
As we mentioned earlier, the exploit kit targets iPhones with older versions of iOS and is ineffective against the latest versions of the system.
See also: Vulnerability in MS-Agent allows complete system compromise
More details on how Corona works, as well as the full list of vulnerabilities used, can be found in the full post on the Google Cloud Blog.
iVerify also published a report on Corona, suggesting that it appears to share the same underpinnings as known US government hacking tools .

“This is the first observed mass exploitation of mobile phones, including iOS, by a criminal group using tools likely made by a state,” the company commented.
Despite Coruna's apparent common roots with hacking tools linked to the US government, the exploit appears to have been leaked and deployed in campaigns by Russian spies and Chinese cybercriminals.
See also: Chrome Vulnerability: Malicious Extensions and Gemini Panel
Reports last year showed that the spyware had expanded its targets beyond civil society, such as journalists and dissidents, to include executives in technology and financial services, political campaigns and other influential individuals. The more widespread the use, the more certain a leak is to occur.

The exploit kit was delivered via “watering hole” attacks on compromised websites, including fake cryptocurrency services designed to lure victims to malicious pages. The final payload appears to be financially motivated, with modules designed to extract cryptocurrency wallet data and recovery phrases from infected devices.
