s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ios.coruna

📛 Threat Title

Malware family: Coruna

Category: Coruna First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ios.coruna`. Printable name: Coruna.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ios.coruna VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.coruna

IOC database

Type
domain
Value
ios.coruna
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ios.coruna

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.coruna

References (1)

Remediations (10)

  • web:cloud.google.com

    The exploit kit, named " Coruna " by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypasses.

  • web:github.com

    The leaked exploit toolkit for various iOS versions - khanhduytran0/ coruna

  • web:iverify.io

    iPhones running iOS 13-17.2.1 are at risk. Here's what Coruna does, why it matters, and the steps you can take to detect and defend against it.

  • web:malpedia.caad.fkie.fraunhofer.de

    The exploit kit, named " Coruna " by its developers, contained five full iOS exploit chains and a total of 23 exploits. The core technical value of this exploit kit lies in its comprehensive collection of iOS exploits, with the most advanced ones using non-public exploitation techniques and mitigation bypasses.

  • web:securelist.com

    Kaspersky GReAT experts look into the Coruna exploit kit targeting iPhones. We discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 is an updated version of the Operation Triangulation exploit.

  • web:thehackernews.com

    Google uncovered Coruna iOS exploit kit with 23 exploits across five chains targeting iPhones running iOS 13-17.2.1.

  • web:www.bleepingcomputer.com

    A previously undocumented set of 23 iOS exploits named " Coruna " has been deployed by multiple threat actors in targeted espionage campaigns and financially motivated attacks.

  • web:www.forbes.com

    An iOS warning has been issued by researchers after they discovered "a new and powerful" exploit kit targeting Apple iPhone models running iOS version 13 to 17.2.1. Dubbed " Coruna " by its ...

  • web:www.kaspersky.com

    Kaspersky's Global Research and Analysis Team (GReAT) conducted a code-level analysis of Coruna's exploits and determined that the kit is a direct, updated iteration of the framework that was at least partially used in the Operation Triangulation cyber-espionage campaign. Kaspersky is confident that the kernel exploits in both Triangulation and Coruna were created by the same author.

  • web:www.privacyguides.org

    The kit, dubbed Coruna internally by its developers, contained five full iOS exploit chains and 23 total exploits, some of which were non-public exploits and mitigation bypasses. GTIG initially tracked it through its use by a customer of a surveillance vendor, a seller of spyware that's used against targeted individuals' devices.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.