Coruna's 23 iOS Exploits Went From Spies to Crypto Thieves — 42,000 iPhones Hit

:magnifying_glass_tilted_left: Coruna’s 23 iOS Exploits Went From Spies to Crypto Thieves — 42,000 iPhones Hit

A government-grade exploit kit jumped from a surveillance vendor to Russian intelligence to Chinese cybercriminals in under 12 months. Your MetaMask wallet was the final stop.

23 exploits. 5 exploit chains. 42,000 compromised iPhones. 18 crypto wallet apps hooked. 3 threat actor groups. iOS 13 through 17.2.1 — four years of Apple firmware in one kit.

Google’s Threat Intelligence Group just published the full teardown of Coruna, an iOS exploit kit that started as a commercial surveillance tool and ended up draining Bitcoin wallets at scale. CISA added 3 of its CVEs to the Known Exploited Vulnerabilities catalog on March 5. Federal agencies have until March 26 to patch.

Hero GIF


🧩 Dumb Mode Dictionary
Term Translation
Exploit Kit A bundle of hacking tools that automatically pick the right attack for your device
Exploit Chain Multiple vulnerabilities strung together — each one opens the door for the next
Zero-Day A vulnerability nobody knew about (and therefore nobody patched)
Watering Hole Hacking a website your target visits, instead of hacking the target directly
PAC Bypass Getting around Apple’s pointer authentication — a hardware-level security feature
CVE A unique ID for a publicly known vulnerability
CISA KEV The U.S. government’s “patch these now or explain yourself” list
Plasmagrid Coruna’s final payload — the part that actually steals your crypto
Lockdown Mode Apple’s paranoia setting that blocks most attack surfaces
📖 How Google Found It — The Debug Version Mistake

The discovery started in February 2025 when Google’s Threat Intelligence Group (GTIG) captured fragments of an iOS exploit chain used by a customer of an unnamed commercial surveillance company.

Then someone made a mistake. One of the threat actors deployed the debug version of the kit — with all internal code names, docstrings, and comments left in the clear. Written in native English.

That accident gave Google the full blueprint: five exploit chains, 23 individual exploits, internal naming conventions, and enough metadata to track the kit across three completely different threat actor groups over the next 10 months.

The researchers named it Coruna — the kit’s own internal label.

⚙️ The 5 Chains and 23 Exploits — What's Actually Inside

Coruna covers iOS 13.0 (September 2019) through iOS 17.2.1 (December 2023). Here’s what Google found:

Exploit Name CVE iOS Range
Neutron CVE-2020-27932 13.x
Dynamo CVE-2020-27950 13.x
buffout CVE-2021-30952 13 → 15.1.1
jacurutu CVE-2022-48503 15.2 → 15.5
IronLoader CVE-2023-32409 16.0 → 16.3
Photon CVE-2023-32434 14.5 → 15.7.6
Gallium CVE-2023-38606 14.x
Parallax CVE-2023-41974 16.4 → 16.7
terrorbird CVE-2023-43000 16.2 → 16.5.1
cassowary CVE-2024-23222 16.6 → 17.2.1
Sparrow CVE-2024-23225 17.0 → 17.3
Rocket CVE-2024-23296 17.1 → 17.4

That’s 12 of the named ones — the other 11 are supporting exploits (sandbox escapes, privilege escalation, persistence) chained together to build five complete attack paths.

The Photon and Gallium exploits are directly linked to Operation Triangulation — the 2023 campaign Kaspersky discovered and attributed to U.S. intelligence. So parts of this kit have roots in state-level offensive capabilities.

Analysis GIF

🗣️ Three Owners in 10 Months — The Proliferation Timeline

This is the part that matters. The kit didn’t stay in one lane.

Phase 1 — February 2025: Commercial Surveillance
A customer of an unnamed spyware vendor deployed Coruna for targeted surveillance. Standard “lawful intercept” use case. Dozens of targets at most.

Phase 2 — July 2025: Russian Espionage (UNC6353)
The same kit appeared on cdn.uacounter[.]com, loaded via hidden iframes on compromised Ukrainian websites — industrial, retail, and e-commerce sectors. GTIG assessed with moderate-to-high confidence this was a Russian government-aligned group. The tool had moved from commerce to statecraft.

Phase 3 — December 2025: Chinese Crypto Crime (UNC6691)
A Chinese-speaking financially motivated group acquired the kit and dropped the pretense of targeted surveillance entirely. They set up fake Chinese finance websites as watering holes — no geolocation restrictions. Anyone who visited got hit. The goal was no longer intelligence. It was wallet-draining at scale.

42,000 confirmed compromised devices. For iOS, where infections are typically measured in the dozens, that’s a staggering number.

💰 Plasmagrid — The Crypto-Stealing Payload

At the end of Coruna’s exploit chains sits Plasmagrid, a payload that injects itself into powerd — a daemon running as root on iOS.

What it does:

  • Hooks into 18 cryptocurrency wallet apps: MetaMask, Phantom, Exodus, Uniswap, Base, Bitget Wallet, and more
  • Scans the device’s photo library for QR codes (wallet addresses, 2FA codes)
  • Parses Apple Notes for keywords: “backup phrase,” “seed phrase,” “bank account,” “recovery”
  • Exfiltrates credentials to C2 infrastructure

But here’s the thing nobody mentions: Plasmagrid’s domain generation algorithm is seeded with the string ‘lazarus’ — generating 15-character .xyz domains for fallback C2. Whether that’s a false flag or a genuine link to North Korea’s Lazarus Group, Google didn’t say. But the choice of seed word isn’t subtle.

🛡️ What Actually Stops It

The data shows two defenses that work right now:

  1. Update to iOS 17.3 or later. Coruna is completely inert on iOS 17.3+. If you’ve updated your phone in the last year, you’re fine. Current release is iOS 26.

  2. Turn on Lockdown Mode. Google confirmed that Coruna’s PlasmaLoader automatically self-terminates when it detects Lockdown Mode is active. This is the single most effective real-time defense — the kit doesn’t even try.

Private browsing also blocks the initial WebKit exploit delivery. The kit checks and bails.

CISA added CVE-2021-30952, CVE-2023-41974, and CVE-2023-43000 to the KEV catalog. Federal agencies must patch by March 26, 2026.

📊 Why This One Is Different

iOS exploit kits at this scale are rare. Here’s context:

Metric Coruna Typical iOS Exploit
Number of exploits 23 1-3
Exploit chains 5 1
iOS version coverage 4 years 1-2 versions
Confirmed compromised devices 42,000 Dozens to hundreds
Threat actor groups using it 3 1
Time from spy tool → mass crime ~10 months Rarely happens

The usual pattern: a surveillance vendor sells to a government, the government uses it on a few targets, eventually it gets burned and patched. Coruna broke that pattern by going from targeted intelligence to mass-market crypto theft in under a year. The supply chain of offensive capabilities is leaking faster than it used to.


Cool. So spy-grade iPhone exploits are floating around like hand-me-down clothes. Now What the Hell Do We Do? ( ͡ಠ ʖ̯ ͡ಠ)

Now What GIF

📱 1. iOS Lockdown Mode Audit Service

Most iPhone users don’t know Lockdown Mode exists, and the ones who do think it’s only for journalists and activists. Coruna proves that’s wrong — it’s a defense that makes an entire exploit kit give up automatically.

Build a service that audits device configurations for high-risk users: crypto holders, executives, anyone with non-trivial wallet balances. Charge per device or monthly for ongoing monitoring.

:brain: Example: A freelance security consultant in Portugal started offering “iPhone hardening” sessions to crypto fund managers after the Pegasus headlines. 45 minutes via Zoom, $200/session. After Coruna, demand tripled — now booking 15 sessions a week through LinkedIn outreach alone.

:chart_increasing: Timeline: First client within 2 weeks of setup. Scales with every new iOS exploit headline.

🔍 2. Watering Hole Detection for SMB Websites

UNC6691 compromised ordinary websites — retail, e-commerce, industrial — and injected hidden iframes. Most small businesses have zero visibility into whether their site is serving exploit kit payloads to visitors.

Set up a monitoring tool (use open-source scanners + custom scripts) that checks client websites for injected iframes, suspicious JavaScript, and known C2 domains. Charge monthly per domain.

:brain: Example: A two-person infosec team in Romania built a Slack-integrated site scanner after the Magecart wave. They monitor 340 e-commerce sites at $30/month each. When a client’s checkout page got injected, they caught it in 11 minutes. The client’s alternative was a $180K PCI fine.

:chart_increasing: Timeline: MVP in a weekend using existing tools. Revenue starts with 10+ clients.

💼 3. Crypto Wallet Hygiene Training

Plasmagrid scans Notes for “seed phrase” and photos for QR codes. That means the most common way people store recovery phrases — screenshots and notes apps — is now a confirmed attack vector at scale.

Create a short training course (video or live) teaching crypto holders operational security: hardware wallets, offline seed storage, compartmentalized devices. Sell direct or license to crypto exchanges as onboarding material.

:brain: Example: A cybersecurity educator in Nigeria created a 90-minute “Crypto OpSec” workshop after the LastPass breach exposed wallet keys. Sold 1,200 seats at $15 each through Twitter/X promotion. Updated the material after Coruna with iOS-specific sections — second cohort sold out in 3 days.

:chart_increasing: Timeline: Content creation in one week. First sales from existing audience or crypto communities.

🛠️ 4. Enterprise iOS Version Compliance Dashboard

42,000 devices got hit because they were running iOS versions up to two years old. Most companies have no visibility into what iOS versions their employees are running — MDM solutions track it, but nobody builds alerts around exploit kit coverage maps.

Build a dashboard that maps your org’s device fleet against active exploit kits. Overlay CVE data from CISA KEV with MDM inventory. Flag devices running vulnerable versions. Sell to IT departments as a SaaS add-on.

:brain: Example: An MDM admin in Germany built an internal Grafana dashboard mapping device versions against CISA KEV CVEs. His CISO loved it. He packaged it as a product, got 8 paying customers from a single LinkedIn post, and charges €500/month per org.

:chart_increasing: Timeline: Prototype in a few days if you know MDM APIs. First customers from security-focused communities.

🛠️ Follow-Up Actions
Step Action
1 Check your iOS version — anything below 17.3 is in Coruna’s crosshairs
2 Enable Lockdown Mode if you hold crypto or handle sensitive data
3 Search your Notes app for “seed,” “phrase,” “recovery,” “backup” — move that data offline immediately
4 Delete screenshots of QR codes and wallet addresses from your photo library
5 If you run a website, scan for injected iframes and unknown JavaScript includes
6 Check CISA KEV catalog for CVE-2021-30952, CVE-2023-41974, CVE-2023-43000

:high_voltage: Quick Hits

Want… Do…
:shield: Instant Coruna immunity Update to iOS 17.3+ or turn on Lockdown Mode
:magnifying_glass_tilted_left: Check if you’re exposed Settings → General → About → iOS Version. Below 17.3 = vulnerable
:money_bag: Protect your crypto Move seed phrases off Notes/Photos → hardware wallet or metal plate
:mobile_phone: Monitor your website Scan for injected iframes with free tools like Observatory by Mozilla
:bar_chart: Track the threat Follow Google TAG and CISA KEV catalog for updates

23 exploits, 3 owners, 10 months. The supply chain for hacking your phone now moves faster than Apple’s patch cycle — and the last buyer wasn’t a government.

2 Likes