Security researchers have linked the coruna exploit kit to a renewed wave of targeted iPhone attacks, reviving techniques first seen in Operation Triangulation.
On March 4, 2026, Google and iVerify disclosed a highly sophisticated exploit framework targeting Apple iPhone devices. According to Google, the toolkit was initially found in attacks by a customer of an unnamed surveillance vendor and later in watering-hole operations in Ukraine and financially motivated intrusions in China.
During that research, analysts uncovered a debug build of the toolkit that exposed internal exploit labels and the framework’s name: Coruna. Moreover, inspection showed the framework combined multiple already patched bugs with fresh weaponizations of CVE-2023-32434 and CVE-2023-38606, two vulnerabilities first observed as zero-days in Operation Triangulation.
Operation Triangulation itself is a complex mobile APT campaign against iOS devices. It was discovered after suspicious traffic appeared on a corporate Wi


