Initially observed in targeted surveillance operations, Coruna later appeared in watering-hole attacks against Ukrainian users and eventually in financially motivated campaigns targeting cryptocurrency users. This progression reflects a broader trend in which advanced mobile exploitation capabilities originally developed for nation-state operations begin to proliferate across criminal ecosystems.
“Mobile exploit kits like Coruna demonstrate how quickly sophisticated attack capabilities can spread beyond highly targeted campaigns into broader criminal activity,” said Nicolás Chiaraviglio, Chief Scientist at Zimperium. “As mobile devices increasingly serve as a gateway to enterprise systems, organizations need layered, on-device security that can detect threats across the entire mobile attack chain.”
Advanced exploit kits typically rely on a multi-stage attack process that begins with a malicious website or phishing lure, followed by browser exploitation, privilege escalation, and spyware installation. Because these attacks unfold across several stages, layered mobile security can identify malicious activity at multiple points in the attack lifecycle.
Zimperium’s Mobile Threat Defense (MTD) platform addresses this challenge through on-device detection layers that monitor malicious web activity, suspicious messaging campaigns, abnormal application behavior, and indicators of system compromise. This defense-in-depth approach enables organizations to detect threats before exploitation occurs and identify behavioral signals associated with advanced spyware and privilege-escalation activity.
The emergence of exploit kits like Coruna reinforces a growing reality: mobile devices are now deeply integrated into enterprise environments and serve as a gateway to sensitive systems, corporate communications, and authentication services. As mobile exploitation frameworks continue to evolve, organizations must adopt layered mobile security capable of detecting threats before, during, and after exploitation.





