Skip to content

Security1 publisher2 min readPublished

Coruna's iOS exploit kit fired on a live iPhone two months after Google's teardown

Attacker server logs show the Coruna iOS WebKit kit compromising a live iPhone's browser in six seconds, two months after Google published its teardown. It fired with no tap from the user, on a phone still running iOS 15.8.3.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Coruna's iOS exploit kit fired on a live iPhone two months after Google's teardown
Generated illustration

What happened

  • The kit picked one of five WebKit exploits for the visitor's iOS version, and the one it chose could retry up to 20 times before the page gave up.
  • Between 11:48:29 and 11:48:30 the phone downloaded a manifest, a raw blob, and five device-specific binary and library files.
  • The source IP belonged to a Chinese-registered network, and the same address and user-agent ran the entire chain again about three hours later.
  • After the payload arrived, the phone asked for one more module eight times, and the server returned a 404 each time, so it never received it.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Wallet holders are the target this chain reaches for: GTIG says Coruna's PLASMAGRID module hooks 18 cryptocurrency-wallet apps, including MetaMask, Trust Wallet, Phantom and Uniswap.
  • capability One hostile page can work through a range of devices unattended, since it fingerprints each visitor, rejects anything below iOS 13, checks newer devices for simulators, and tests for Lockdown Mode before firing.
  • precedent Publishing a teardown does not take a WebKit kit out of circulation; this operator was still running Coruna against a live phone after Google named it.
  • constraint The logs confirm only the browser stage, showing no later command-server contact, no data theft, and no sign the implant survived a reboot, so the confirmed harm stops at code running in Safari.

C2 Hunters got onto the attacker's server and read its access logs, source code, and staged files [1]. Coruna is an iOS exploit kit aimed at WebKit, the engine behind Safari, and it sat in a directory named coruna-waterhole [2]. A script, server.py, handed out one file, group.html, for any request to the site root, and that page controlled the whole exploit chain [14]. On the target phone it loaded two helper scripts, platform_module.js and utility_module.js [6].

The phone advertised Safari 15.6.6, so the kit reached for the Stage 1 built for that band, codenamed bluebird, which targets iOS 15.6 through 16.1.2 [5][7]. A callback at 11:47:52 reported the browser exploit had finished, a message C2 Hunters says fires only after the payload, bootstrap.dylib, loads into memory and starts [8]. Where a device uses Pointer Authentication, the chain runs a PAC bypass and a sandbox escape, loading Variant B when its checks fail; this phone got Variant B [18].

C2 Hunters is careful about what the record proves. In its account, logs and saved output show what happened, commands and scripts show only what an attacker ran or prepared, and a list of scanned targets is not a list of victims [19].

GTIG published its analysis on March 4. The logged run is 6 May, 63 days later [3][5][1]. C2 Hunters recovered all of this from one operator's server, so the evidence does not show the kit passed around for anyone to reuse [1].

What to watch

  • Whether investigators tie the Chinese-registered source IP and this server to a named threat actor.
  • Whether the missing PLASMAGRID module turns up delivered elsewhere, showing the 18-app wallet-hooking capability firing in the wild.
  • Whether the other four Stage 1 exploits, jacurutu, terrorbird, cassowary and the unnamed fifth, are seen hitting newer iOS builds.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories