Kaspersky researchers say the Coruna iOS exploit framework is an evolution of the toolkit used in the Operation Triangulation espionage campaign and has been updated to target modern Apple hardware and software. Their report shows the framework now includes checks for Apple A17 and M3 chips and supports iOS builds up to 17.2.
The analysis found Coruna contains five full exploit chains that leverage 23 vulnerabilities, including CVE-2023-32434 and CVE-2023-38606, which were also used in Operation Triangulation. Kaspersky said similarities in exploit code and binaries indicate Coruna is a maintained successor to the earlier framework rather than a collection of public exploits.
Kaspersky’s examination outlines an attack flow that begins in Safari with a stager that fingerprints the device, chooses appropriate remote code execution and pointer authentication code exploits, and retrieves encrypted metadata for subsequent stages. Later components are downloaded encrypted, decrypted with ChaCha20, decompressed with LZMA and unpacked from custom container formats.
The framework chooses and launches kernel exploits, Mach-O loaders and launchers based on the device architecture and iOS version. Kaspersky said the payloads support ARM64 and ARM64E architectures and perform explicit checks for A17, M3, M3 Pro and M3 Max processors. Package identifiers and system checks in the code indicate the exploits can target iOS builds earlier than 14.0 beta 7, earlier than 14.7, earlier than 16.5 beta 4, earlier than 16.6 beta 5 and earlier than 17.2.
Boris Larin, principal security researcher at Kaspersky GReAT, warned that Coruna has been observed beyond precision espionage operations and is now appearing in financially motivated campaigns that attempt cryptocurrency theft through fake exchange websites. He said the framework has been continuously updated and is no longer limited to targeted surveillance.
Researchers have also disclosed another iOS exploit kit named DarkSword that is being used by multiple threat actors and, unlike some private toolkits, has become publicly available, increasing the risk that unpatched iPhones could be targeted by a wider range of attackers, according to mobile security companies involved in the disclosure.
Kaspersky noted Operation Triangulation was discovered during internal Wi-Fi monitoring in June 2023 but had been active for years prior, and in late 2023 researchers found the campaign abused undocumented chip features to bypass hardware protections. Apple has published a bulletin to address these issues and said fixes are available through security updates for current and earlier iOS versions.

