logo

Coruna: Inside the Nation-State-Grade iOS Exploit Kit We've Been Tracking

ID: 10775711-aa3a-5ae2-8d1b-fef6b9263ce7

STIX ID: report--10775711-aa3a-5ae2-8d1b-fef6b9263ce7

Feed Name: iVerify Blog

Threat Score
90/100

Date Published: 2026-03-03

Date Updated: 2026-04-28

...
...

iVerify analyzed the Coruna (aka CryptoWaters) iOS exploit kit — a modular 1‑click chain of Safari RCE and local privilege escalation affecting iOS 13–17.2.1 — used in watering‑hole mass exploitation. The chain loads multi‑stage implants (powerd → locationd → process‑injected dylibs) that exfiltrate photos, notes, and target crypto wallets; the report provides capture methodology, extensive IOCs (domains, file paths, user agents, thread/queue names, SHA256s) and downloadable STIX2 indicators for detection and forensic triage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.