Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionageactively-exploited-vulnerabilitygovernment-vulnerability-catalogendpoint-software-vulnerability

Coruna iPhone Exploit Kit Linked to Russian Espionage and Criminal Use

Updated 3mo agoFirst seen Mar 17, 20263 sources

Researchers reported that the Coruna iOS exploitation framework contains full exploit chains and roughly 23 exploits targeting iPhones running iOS 13 through 17.2/17.2.1, and that it has been used by multiple threat actors, including UNC6353, a suspected Russian espionage group conducting watering-hole attacks against Ukrainian users, and UNC6691, a financially motivated China-based actor. The toolkit, also referred to as CryptoWaters, has been described as a rare case of nation-state-grade iPhone exploitation appearing in broader criminal operations, with post-exploitation activity including the PLASMAGRID payload and persistence through a process identified as com.apple.assistd that injects into the powerd daemon running as root.

Reporting also highlighted competing views on the toolkit's origin. One account said evidence suggests parts of Coruna may have originated from Trenchant, a hacking and surveillance division of L3Harris, and later leaked into the wider ecosystem, ultimately reaching foreign intelligence services and cybercriminals. However, technical threat research noted that the definitive origin remains unconfirmed, even as analysts observed reuse of vulnerabilities associated with Operation Triangulation and CISA added CVE-2023-41974 to the Known Exploited Vulnerabilities catalog after Google's publication. The story is substantive threat intelligence, not fluff, because it concerns an active exploit framework, real-world exploitation, and possible proliferation of advanced offensive capabilities.

Share:
Coruna iPhone Exploit Kit Linked to Russian Espionage and Criminal Use
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 16, 20263mo ago

Researchers publicly detail the Coruna iOS exploit framework

Public reporting described Coruna as a sophisticated iPhone exploitation toolkit with more than 20 exploits and full exploit chains affecting iOS 13 through 17.2.1. The analysis also highlighted reuse across espionage and criminal ecosystems and possible links to L3Harris's Trenchant unit through previously stolen tools.

Mar 7, 20264mo ago

CISA adds CVE-2023-41974 to Known Exploited Vulnerabilities catalog

CISA added CVE-2023-41974, a kernel use-after-free vulnerability used in the Coruna exploit chain, to its Known Exploited Vulnerabilities catalog. The action highlighted active exploitation risk and the need for urgent patching.

Jan 1, 20251y ago

UNC6691 deploys Coruna in fake crypto and finance campaigns

A China-based financially motivated actor tracked as UNC6691 used Coruna one-click Safari exploit chains on fake finance and cryptocurrency sites to mass-exploit iPhone users. The campaign delivered the PLASMAGRID payload to steal wallet data, seed phrases, photos, emails, and Apple Notes content.

Jan 1, 20242y ago

Russian-linked UNC6353 targets Ukrainian users with Coruna exploits

Researchers assessed that UNC6353, a suspected Russian espionage group, used the Coruna iOS exploit framework in operations targeting Ukrainian victims, including via compromised websites. The toolkit was used against iPhones running vulnerable iOS versions from 13 through 17.2.

Jan 1, 20233y ago

Operation Triangulation uses related iPhone vulnerabilities against Russian users

Google researchers linked two vulnerabilities later associated with the Coruna toolkit to the Operation Triangulation iPhone hacking campaign targeting users in Russia. This establishes earlier reuse of some of the same exploit components in a separate espionage operation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.