logo

Google uncovers Coruna iOS Exploit Kit targeting iOS 13–17.2.1

ID: 57ccde9c-a4c5-5a75-8925-765805f2750f

STIX ID: report--57ccde9c-a4c5-5a75-8925-765805f2750f

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Google’s Threat Intelligence Group discovered “Coruna” (CryptoWaters), a highly capable iOS exploit kit comprising five exploit chains and 23 exploits that targets iOS 13.0–17.2.1, abuses WebKit RCEs, PAC and PPL/kernel bypasses, and deploys a loader (PlasmaLoader) that installs a financial/crypto-focused infostealer; the kit has been observed in targeted surveillance, Ukrainian watering-hole attacks, and broad Chinese financial scams, with Google publishing IOCs and YARA rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.