logo

Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks

ID: a13b3100-8031-5157-84f9-14c0b292b4d7

STIX ID: report--a13b3100-8031-5157-84f9-14c0b292b4d7

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-03-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Google Threat Intelligence Group (GTIG) uncovered Coruna, a sophisticated iOS exploit kit containing 23 exploits and five full exploit chains that target iOS 13–17.2.1 and use non-public mitigation bypasses; it has been observed in both state-aligned espionage (e.g., UNC6353) and financially motivated campaigns (e.g., UNC6691). The kit fingerprints devices, selects appropriate exploit chains, and can deploy a loader called PlasmaGrid that injects into the iOS root daemon to download modules that steal cryptocurrency wallet recovery phrases and other sensitive data; GTIG published IOCs and recommends updating iOS or enabling Lockdown Mode.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.