The Coruna exploit kit is an evolution of the code used in Operation Triangulation in 2023, according to new findings from Kaspersky . The exploit kit, which targets iPhones running iOS versions 13.0 to 17.2.1 , has evolved from a spying tool into a mass exploitation platform used by cybercriminals for financial gain.

Boris Larin, a principal security researcher at Kaspersky GReAT, noted that initially there was insufficient evidence to link Corona to Operation Triangulation. However, detailed analysis revealed that the kernel exploits for both campaigns were created by the same author, with Corona being an evolution of the original framework.
See also: Apple: New iOS and iPadOS updates address Coruna exploit
The Coruna iOS Kit contains five complete exploit chains and a total of 23 exploits, including CVE-2023-32434 and CVE-2023-38606. These vulnerabilities were originally used as zero-days in Operation Triangulation, a sophisticated campaign targeting iOS.
Technical Details of the Coruna iOS Kit
Kaspersky 's analysis revealed that Corona supports Apple 's latest processors , including the A17 , M3 , M3 Pro , and M3 Max . It also includes checks for iOS 17.2 and the beta version of iOS 16.5 beta 4 , which fixed the four vulnerabilities exploited by Operation Triangulation .
The attack begins when a user visits a compromised website via Safari. A stager identifies the browser and provides the appropriate exploit based on the browser version and operating system. A payload is then executed that triggers the kernel exploit and allows the final implant to be installed.
See also: Kaspersky: Eliminates the "Operation Triangulation" threat

The framework uses sophisticated techniques to bypass memory protection mechanisms and kernel-mode PAC evasion to avoid the hardware-level protections of Apple.
Spread and Use by Threat Actors
Initially Coruna has now been adopted by a number of threat actors, including a Russian state-run hacking group (which used it in watering hole attacks in Ukraine) and the Chinese UNC6691 (which used it in mass exploitation campaigns).
Google Threat Intelligence Group and iVerify first documented Coruna earlier this month, revealing that it targets iPhone models running iOS versions between 13.0 and 17.2.1 . The kit includes additional vulnerabilities such as CVE-2024-23225 , CVE-2024-23296 , CVE-2024-23222 , and CVE-2022-48503 , which were added to the CISA Known Exploited Vulnerabilities list .

Impact and Protection Measures
According to the data, Coruna has compromised thousands of iPhone in mass attacks. Experts warned that the framework, originally developed for cyber-espionage purposes, is now being used by cybercriminals of various stripes, putting millions of users with unpatched devices at risk.
See also: Apple: Old iPhones vulnerable to Coruna and DarkSword exploits
To protect against the Coruna iOS Kit, experts recommend immediately updating to the latest iOS. Additionally, enabling Lockdown Mode may block the delivery of the kit, while users should avoid untrusted websites.
This development coincides with the leak of a new version of the iPhone exploit kit DarkSword on GitHub, which raises concerns about more attacks. Due to its modular design and ease of reuse, it is expected that other threat actors will begin to incorporate the framework into their attacks, according to The Hacker News.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
