Coruna: A Leaked Government Exploit Kit Is the EternalBlue of Mobile
The First Mass-Scale iOS Attack
Three independent intelligence streams confirmed today what mobile security researchers have feared since Operation Triangulation in 2023: a U.S. government-origin iOS exploit kit has leaked and proliferated into the hands of multiple adversary groups. The kit — called Coruna — chains 23 separate vulnerabilities to achieve zero-click compromise of iPhones running iOS 13 through 17.2.1. At least 42,000 devices are confirmed compromised, with the true number almost certainly higher.
Google's Threat Intelligence Group first identified Coruna in February 2025. iVerify corroborated the analysis and suggested U.S. government origins. The attack vector is a classic watering hole — the target visits a malicious or compromised website, and the phone is owned. No taps, no installs, no user interaction.
Why This Is EternalBlue-Scale
The parallel to EternalBlue is deliberate and precise. In 2017, NSA exploit tools leaked by the Shadow Brokers fueled WannaCry (200,000+ systems) and NotPetya. Coruna follows the same pattern: government offensive tools leaking into a 'second-hand zero-day market' where they cascade to less discriminating operators.
| Dimension | EternalBlue (2017) | Coruna (2026) |
|---|---|---|
| Origin | NSA (Shadow Brokers leak) | U.S. government framework (suspected leak) |
| Target | Windows SMB | Apple iOS (13–17.2.1) |
| Exploit Chain | Single vulnerability | 23 chained vulnerabilities |
| Confirmed Scale | 200,000+ (WannaCry alone) | 42,000+ confirmed, likely far higher |
| Current Operators | North Korea, Russia, criminals | Chinese cybercriminals, Russian state actors, spyware vendors |
The 23-vulnerability chain is extraordinary. Commercial spyware like Pegasus typically chains 3-5 exploits. This depth suggests years of development investment and deep iOS internals expertise — likely spanning WebKit renderer bugs, sandbox escapes, kernel exploits, and persistence mechanisms. The breadth across five major iOS versions indicates the toolkit was actively maintained before proliferation.
Any employee browsing a compromised website on a vulnerable iPhone is silently owned — this includes news sites, industry forums, and supply chain vendor portals that threat actors commonly target as watering holes.
What We Don't Know Yet
No CVEs have been publicly assigned. This suggests either coordinated disclosure is in progress or Apple hasn't fully characterized the exploit chain. Watch Apple's next security advisory closely. Specific IOCs from Google TAG and iVerify should be expected within days.
What to do
Query MDM immediately for any iPhone running iOS below 17.3 — push forced updates or quarantine non-compliant devices from corporate resources within 24 hours
Enable Apple Lockdown Mode on devices belonging to executives, IT administrators, finance personnel, and anyone with production access by end of week
Deploy iVerify or equivalent mobile threat detection across managed and BYOD iOS devices within 7 days to scan for Coruna indicators as IOCs are released
Verify web content filtering blocks uncategorized and newly registered domains across all network egress points this week