New Research Reveals Sophisticated Exploit Framework Targeting iOS Devices, Highlighting Expanding Mobile Attack Surface for Enterprises

Zimperium highlighted the enterprise security implications of Coruna, a sophisticated iOS exploit kit recently disclosed by Google’s Threat Intelligence Group. The toolkit contains multiple exploit chains targeting vulnerabilities across iOS versions 13 through 17.2.1, demonstrating the growing scale and sophistication of modern mobile exploitation frameworks.

Initially observed in targeted surveillance operations, Coruna later appeared in watering-hole attacks against Ukrainian users and eventually in financially motivated campaigns targeting cryptocurrency users. This progression reflects a broader trend in which advanced mobile exploitation capabilities originally developed for nation-state operations begin to proliferate across criminal ecosystems.

“Mobile exploit kits like Coruna demonstrate how quickly sophisticated attack capabilities can spread beyond highly targeted campaigns into broader criminal activity,” said Nicolás Chiaraviglio, Chief Scientist at Zimperium. “As mobile devices increasingly serve as a gateway to enterprise systems, organizations need layered, on-device security that can detect threats across the entire mobile attack chain.”

Advanced exploit kits typically rely on a multi-stage attack process that begins with a malicious website or phishing lure, followed by browser exploitation, privilege escalation, and spyware installation. Because these attacks unfold across several stages, layered mobile security can identify malicious activity at multiple points in the attack lifecycle.

Zimperium’s Mobile Threat Defense (MTD) platform addresses this challenge through on-device detection layers that monitor malicious web activity, suspicious messaging campaigns, abnormal application behavior, and indicators of system compromise. This defense-in-depth approach enables organizations to detect threats before exploitation occurs and identify behavioral signals associated with advanced spyware and privilege-escalation activity.

The emergence of exploit kits like Coruna reinforces a growing reality: mobile devices are now deeply integrated into enterprise environments and serve as a gateway to sensitive systems, corporate communications, and authentication services. As mobile exploitation frameworks continue to evolve, organizations must adopt layered mobile security capable of detecting threats before, during, and after exploitation.

Articles similaires

Malware Update

19 August 2026

Zimperium zLabs Uncovers ToxicPanda 2.0, a Significantly More Powerful Android Banking Trojan

News Highlights : • Malware expands targeting to 349 banking, financial, e-wallet, and (…)

Malware Update

19 March 2026

New Zimperium Report Finds Banking Malware Expands Global Reach, Targeting 1,200+ Financial Apps

New Zimperium, the world leader in AI-empowered mobile security, today Report Finds Banking (…)

Malware Update

17 March 2026

Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools

Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools