<div class="block-paragraph_advanced"><h3><span style="vertical-align: baseline;">Introduction</span><strong style="vertical-align: baseline;"> </strong></h3> <p><span style="vertical-align: baseline;">Google Threat Intelligence Group (GTIG) has identified a new and powerful exploit kit targeting Apple </span><span style="vertical-align: baseline;">iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023)</span><span style="vertical-align: baseline;">. </span><span style="vertical-align: baseline;">The exploit kit, named “Coruna” by its developers, contained five full iOS exploit chains and a total of 23 exploits. </span><span style="vertical-align: baseline;">The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypasses. </span></p> <p><span style="vertical-align: baseline;">The Coruna exploit kit provides </span><a href="https://blog.google/threat-analysis-group/state-backed-attackers-and-commercial-surveillance-vendors-repeatedly-use-the-same-exploits/" rel="noopener" target="_blank"><span style="text-decoration: underline; vertical-align: baseline;">another example of how sophisticated capabilities proliferate</span></a><span style="vertical-align: baseline;">. Over the course of 2025, GTIG tracked its use in highly targeted operations initially conducted by a customer of a </span><a href="https://storage.googleapis.com/gweb-uniblog-publish-prod/documents/Buying_Spying_-_Insights_into_Commercial_Surveillance_Vendors_-_TAG_report.pdf" rel="noopener" target="_blank"><span style="text-decoration: underline; vertical-align: baseline;">surveillance vendor</span></a><span style="vertical-align: baseline;">, then observed its deployment in watering hole attacks targeting Ukrainian users by UNC6353, a suspected Russian espionage group. We then retrieved the complete exploit kit when i
CRITICAL
research
Threat Intelligence
Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
CyberHawk Threat Intel — IOC Scanner, Live IOC Feed (3.6M+ indicators), Infostealer Intelligence, Threat Map, MISP Feeds, GitHub Arsenal, Courses and more. Free to join.
Register Free →
Source Attribution
This intelligence summary is sourced from Mandiant Blog and curated by CyberHawk Threat Intel for the security community. Read the complete article at the source link.
Read original at Mandiant Blog →
This intelligence summary is sourced from Mandiant Blog and curated by CyberHawk Threat Intel for the security community. Read the complete article at the source link.
Read original at Mandiant Blog →
Accelerate Your Security Operations
CyberHawk Threat Intel is a complete Cyber Intelligence Platform — one place for every tool a security professional needs. Built by Rudra Verma, Senior Security Architect and Researcher, CyberHawk Consultancy.
IOC Scanner — scan any domain, IP, hash, URL
Live IOC Feed — 3.6M+ indicators, filterable
Infostealer Intelligence — live compromised creds
Live Threat Map — real-time global attack vectors
MISP Threat Feeds — CIRCL, Feodo, Botvrij, more
GitHub Arsenal — curated security tools and scripts
Security Blog — CVE advisories and threat research
Video Courses — cybersecurity training and education
SOPs and Playbooks — SecOps procedures
Analyst Library — references and toolkits
Scan Reports — historical threat intelligence
Cyber News — this feed, aggregated in-platform