Coruna: Spy-grade iOS exploit kit powering financial crime

2026-03-04T21:08:09Z8701420bf082259ed48b76bbaddc8537e24cd56fd785b889cb739b4e0f5c7e68
CloudflareCorunaGTIGGoogle Threat Intelligence GroupOAuthTPMSTPRMcredential-theftexploit-kitfinancial-crimeiOSidentity-governancemobile-exploitphishingprivacy-trackingsecure-by-designstate-linkedthird-party-riskthreat-telemetryzero-trust

What happened

This feed highlights multiple security developments. Top story: Google TAG reports a powerful iOS exploit kit called “Coruna” circulated among commercial surveillance groups, state-linked actors and financially motivated criminals; Coruna reportedly contains five full iOS exploit chains and 23 exploits (including CVE-tracked flaws). Microsoft researchers disclose active phishing campaigns abusing OAuth redirection logic to bypass defenses and deliver malware or harvest credentials targeting government/public-sector organizations. Additional items: Cloudflare’s Cyber Threat Report cites ~230B+/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
8701420bf082259ed48b76bbaddc8537e24cd56fd785b889cb739b4e0f5c7e68
Enrichment time
2026-03-04T21:08:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.