Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
Essential information
- Published
- 03/03/2026 15:42
- Modified
- 03/03/2026 16:45
- Tags
- 2026-03-03 CVE-2020-27932 CVE-2020-27950 CVE-2021-30952 CVE-2022-48503 CVE-2023-32409 CVE-2023-32434 CVE-2023-38606 CVE-2023-41974 CVE-2023-43000 CVE-2024-23222 CVE-2024-23225 CVE-2024-23296 coruna cryptocurrency exploit-kit financial theft ios plasmagrid surveillance zero-day
- Related entities
- 12 vulnerabilities (cve), 77 observables, 1 intrusion sets (apt), 14 techniques (mitre), 2 malware, 60 others
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (12)
Apple iOS and iPadOS contain a use-after-free vulnerability. An app may be able to execute arbitrary code with kernel privileges.
- Attack vector
- LOCAL
- Published
- 10/01/2024
- Modified
- 15/03/2026
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, …
- Attack vector
- NETWORK
- Published
- 05/11/2025
- Modified
- 15/03/2026
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted …
- Attack vector
- Network
- Complexity
- LOW
- Published
- 23/01/2024
- Modified
- 04/04/2026
Apple iOS. iPadOS, macOS, and watchOS contain an integer overflow vulnerability that could allow an application to execute code with kernel privileges.
- Attack vector
- Local
- Published
- 23/06/2023
- Modified
- 03/03/2026
Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit contain an unspecified vulnerability that can allow a remote attacker to break out …
- Attack vector
- Network
- Published
- 22/05/2023
- Modified
- 03/03/2026
Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and …
- Attack vector
- Local
- Complexity
- LOW
- Published
- 05/03/2024
- Modified
- 04/04/2026
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.
- Attack vector
- Local
- Published
- 26/07/2023
- Modified
- 21/12/2025
Apple iOS, iPadOS, macOS, and watchOS contain a memory initialization vulnerability that may allow a malicious application to disclose kernel memory.
- Published
- 03/11/2021
- Modified
- 03/03/2026
Apple tvOS, macOS, Safari, iPadOS and watchOS contain an integer overflow or wraparound vulnerability due to the processing of maliciously crafted web …
- Attack vector
- LOCAL
- Published
- 24/08/2021
- Modified
- 10/03/2026
Apple iOS, iPadOS, macOS, and watchOS contain a type confusion vulnerability that may allow a malicious application to execute code with kernel …
- Published
- 03/11/2021
- Modified
- 03/03/2026
Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary …
- Attack vector
- Network
- Published
- 20/10/2025
- Modified
- 03/03/2026
Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read …
- Attack vector
- Local
- Complexity
- LOW
- Published
- 05/03/2024
- Modified
- 04/04/2026
Observables (77)
-
499f6b1e012d9bc947eea8e23635dfe6464cd7c9d99eb11d5874bd7b613297b1 -
721b46b43b7084b98e51ab00606f08a6ccd30b23bef5e542088f0b5706a8f780 -
1fb9dedf1de81d387eff4bd5e747f730dd03c440157a66f20fdb5e95f64318c0 -
05b5e4070b3b8a130b12ea96c5526b4615fcae121bb802b1a10c3a7a70f39901 -
d517c3868c5e7808202f53fa78d827a308d94500ae9051db0a62e11f7852e802 -
3c297829353778857edfeaed3ceeeca1bf8b60534f1979f7d442a0b03c56e541 -
be28b40df919d3fa87ed49e51135a719bd0616c9ac346ea5f20095cb78031ed9 -
42cc02cecd65f22a3658354c5a5efa6a6ec3d716c7fbbcd12df1d1b077d2591b -
2a9d21ca07244932939c6c58699448f2147992c1f49cd3bc7d067bd92cb54f3a -
4dc255504a6c3ea8714ccdc95cc04138dc6c92130887274c8582b4a96ebab4a8 -
0dff17e3aa12c4928273c70a2e0a6fff25d3e43c0d1b71056abad34a22b03495 -
023e5fb71923cfa2088b9a48ad8566ff7ac92a99630add0629a5edf4679888de
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Techniques (MITRE) (14)
-
Virtualization/Sandbox Evasion MITRE
-
Input Capture MITRE
-
Process Injection MITRE
-
Credentials from Password Stores MITRE
-
Software Discovery MITRE
-
Native API MITRE
-
Acquire Infrastructure MITRE
-
Exploit Public-Facing Application MITRE
-
Remote Access Tools MITRE
-
Command and Scripting Interpreter MITRE
-
File and Directory Discovery MITRE
-
Stage Capabilities MITRE
Malware (2)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Others (60)
-
xmmfrkq9oat1daq.xyz
-
gqjs3ra34lyuvzb.xyz
-
xfal48cf0ies7ew.xyz
-
vvri8ocl4t3k8n6.xyz
-
sf2bisx5nhdkygn3l.xyz
-
gdvynopz3pa0tik.xyz
-
kanav.blog
-
i.binaner.com
-
ios.teegrom.top
-
anygg.liquorfight.com
-
res54allb.xn--xkrsa0078bd6d.com
-
land.77bingos.com