The Containment Era is here. →Explore

Executive Summary

In 2025, the Coruna exploit kit emerged as a sophisticated tool targeting iPhones running iOS versions 13.0 through 17.2.1. Initially observed in February 2025, it was used by a surveillance vendor's client, later appearing in attacks by Russian espionage groups against Ukrainian users, and subsequently by financially motivated Chinese hackers. Coruna comprises five full iOS exploit chains leveraging 23 vulnerabilities, including CVE-2023-32434 and CVE-2023-38606, previously exploited in Operation Triangulation. The kit's evolution suggests a continuous development from earlier frameworks, now capable of compromising modern hardware, including Apple's A17 and M3 chips. (helpnetsecurity.com)

The proliferation of Coruna underscores the escalating risk of advanced exploit kits transitioning from state-sponsored espionage to widespread cybercrime. This trend highlights the urgent need for organizations to implement robust security measures, including timely software updates and advanced threat detection systems, to mitigate the risks posed by such sophisticated tools.

Why This Matters Now

The Coruna exploit kit's transition from targeted espionage to widespread cybercrime exemplifies the rapid dissemination of advanced hacking tools. Organizations must prioritize updating their security protocols and systems to defend against these evolving threats.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Coruna is a sophisticated exploit kit targeting iPhones running iOS 13.0 through 17.2.1, comprising five exploit chains and 23 vulnerabilities, including those used in Operation Triangulation.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust Cloud Native Security Fabric (CNSF) is pertinent to this incident as it embeds security directly into the cloud infrastructure, potentially limiting the attacker's ability to move laterally and exfiltrate data.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix CNSF primarily secures cloud workloads, its principles of embedded security could inspire similar protections in device communications, potentially reducing the success rate of such exploits.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Applying Zero Trust principles could limit the scope of privilege escalation by enforcing strict access controls, potentially reducing the attacker's ability to gain elevated privileges.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Enforcing east-west traffic security could limit the malware's ability to move laterally within the device, potentially reducing access to sensitive subsystems and data.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Enhanced visibility and control over network communications could limit the establishment of unauthorized command and control channels, potentially reducing remote control capabilities.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Enforcing strict egress policies could limit unauthorized data exfiltration, potentially reducing the amount of sensitive information transmitted to external servers.

Impact (Mitigations)

By constraining earlier stages of the attack, the overall impact on user privacy and device integrity could be limited, potentially reducing the risk of further exploitation or surveillance.

Impact at a Glance

Affected Business Functions

  • Mobile Device Security
  • Data Privacy Compliance
  • Financial Transactions
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of sensitive user data due to device compromise.

Recommended Actions

  • Implement Zero Trust Segmentation to restrict lateral movement within devices and limit access to sensitive subsystems.
  • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
  • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual device behaviors indicative of compromise.
  • Ensure regular updates and patch management to mitigate known vulnerabilities exploited by such malware.
  • Educate users on the risks of zero-click exploits and the importance of maintaining device security settings.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image