{"id":2143,"date":"2026-03-26T08:04:31","date_gmt":"2026-03-26T08:04:31","guid":{"rendered":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/"},"modified":"2026-03-26T08:04:31","modified_gmt":"2026-03-26T08:04:31","slug":"coruna-the-framework-used-in-operation-triangulation","status":"publish","type":"post","link":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/","title":{"rendered":"Coruna: the framework used in Operation Triangulation"},"content":{"rendered":"<div>\n<p><img loading=\"lazy\" width=\"990\" height=\"400\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg\" class=\"attachment-securelist-huge-promo size-securelist-huge-promo wp-post-image\" alt=\"\" decoding=\"async\"><\/p>\n<h2 id=\"introduction\">Introduction<\/h2>\n<p>On March 4, 2026, <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/coruna-powerful-ios-exploit-kit\" target=\"_blank\" rel=\"noopener\">Google<\/a> and <a href=\"https:\/\/iverify.io\/blog\/coruna-inside-the-nation-state-grade-ios-exploit-kit-we-ve-been-tracking\" target=\"_blank\" rel=\"noopener\">iVerify<\/a> published reports about a highly sophisticated exploit kit targeting Apple iPhone devices. According to Google, the exploit kit was first discovered in targeted attacks conducted by a customer of an unnamed surveillance vendor. It was later used by other attackers in watering-hole attacks in Ukraine and in financially motivated attacks in China. Additionally, researchers discovered an instance with the debug version of the exploit kit, which revealed the internal names of the exploits and the framework name used by its developers \u2014 Coruna. Analysis of the kit showed that it relies on the exploitation of many previously patched vulnerabilities and also includes exploits for <a href=\"https:\/\/support.apple.com\/en-us\/103837\" target=\"_blank\" rel=\"noopener\">CVE-2023-32434<\/a> and <a href=\"https:\/\/support.apple.com\/en-us\/120338\" target=\"_blank\" rel=\"noopener\">CVE-2023-38606<\/a>. These two vulnerabilities particularly caught our attention because they had been first discovered as zero-days used in <a href=\"https:\/\/securelist.com\/trng-2023\/\" target=\"_blank\" rel=\"noopener\">Operation Triangulation<\/a>.<\/p>\n<p>Operation Triangulation is a complex mobile APT campaign targeting iOS devices. We discovered it while monitoring the network traffic of our own corporate Wi-Fi network. We noticed suspicious activity that originated from several iOS-based phones. Following the investigation, we learned that this campaign employed a sophisticated spyware implant and multiple zero-day exploits. The investigation lasted for over six months, during which <a href=\"https:\/\/securelist.com\/trng-2023\/\" target=\"_blank\" rel=\"noopener\">we disclosed our findings<\/a> in connection to the attack. Kaspersky GReAT experts also <a href=\"https:\/\/media.ccc.de\/v\/37c3-11859-operation_triangulation_what_you_get_when_attack_iphones_of_researchers\" target=\"_blank\" rel=\"noopener\">presented these findings<\/a> at the 37th Chaos Communication Congress (37C3).<\/p>\n<p>Although all the details of both CVE-2023-32434 and CVE-2023-38606 have long been publicly available, and other researchers have developed their own exploits without ever seeing the Triangulation code, we decided to closely investigate the exploits used in Coruna. Some of the exploit kit distribution links provided by Google remained active at the time the report was published, which allowed us to collect, decrypt, and analyze all components of Coruna.<\/p>\n<p>During our analysis, we discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 vulnerabilities used in Coruna, in fact, is an updated version of the same exploit that had been used in Operation Triangulation. The images below illustrate a high-level overview of the two attack chains. The exploit in question is highlighted with a red rectangle.<\/p>\n<div id=\"attachment_119239\" style=\"width: 1930px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1.png\" class=\"magnificImage\"><img fetchpriority=\"high\" decoding=\"async\" aria-describedby=\"caption-attachment-119239\" class=\"size-full wp-image-119239\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1.png\" alt=\"Attack chain of Operation Triangulation (simplified)\" width=\"1920\" height=\"1080\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1.png 1920w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1-300x169.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1-1024x576.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1-768x432.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1-1536x864.png 1536w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1-800x450.png 800w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1-622x350.png 622w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1-740x416.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160655\/coruna-framework1-498x280.png 498w\" sizes=\"(max-width: 1920px) 100vw, 1920px\"><\/a><\/p>\n<p id=\"caption-attachment-119239\" class=\"wp-caption-text\">Attack chain of Operation Triangulation (simplified)<\/p>\n<\/div>\n<div id=\"attachment_119240\" style=\"width: 1930px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-119240\" class=\"size-full wp-image-119240\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2.png\" alt=\"Attack chain of Coruna (simplified)\" width=\"1920\" height=\"1080\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2.png 1920w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2-300x169.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2-1024x576.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2-768x432.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2-1536x864.png 1536w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2-800x450.png 800w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2-622x350.png 622w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2-740x416.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/24160740\/coruna-framework2-498x280.png 498w\" sizes=\"auto, (max-width: 1920px) 100vw, 1920px\"><\/a><\/p>\n<p id=\"caption-attachment-119240\" class=\"wp-caption-text\">Attack chain of Coruna (simplified)<\/p>\n<\/div>\n<p>Moreover, we discovered that Coruna includes four additional kernel exploits that we had not seen used in Operation Triangulation, two of which were developed after the discovery of Operation Triangulation. All of these exploits are built on the same kernel exploitation framework and share common code. Code similarities from kernel exploits can also be found in other components of Coruna. These findings led us to conclude that this exploit kit was not patchworked but rather designed with a unified approach. We assume that it\u2019s an updated version of the same exploitation framework that was used \u2014 at least to some extent \u2014 in Operation Triangulation.<\/p>\n<h2 id=\"technical-details\">Technical details<\/h2>\n<p>While we continue to investigate all exploits and vulnerabilities used by Coruna, this post provides a high-level overview of the exploit kit and attack chain.<\/p>\n<h3 id=\"safari\">Safari<\/h3>\n<p>Exploitation begins with a stager that fingerprints the browser and selects and executes appropriate remote code execution (RCE) and pointer authentication code (PAC) exploits depending on the browser version. It also contains a URL to an encrypted file with information about all available packages containing exploits and other components. The stager also includes a 256-bit key used to decrypt it. The URL and decryption key are passed to a payload embedded in PAC exploits.<\/p>\n<h3 id=\"payload\">Payload<\/h3>\n<p>The payload is responsible for initiating the exploitation of the kernel. After initialization, the payload first downloads a file with information about other available components. To extract it, the payload performs several steps processing multiple file formats.<\/p>\n<p>First, the downloaded file is decrypted using the ChaCha20 stream cipher. Decryption yields a container with the magic number 0xBEDF00D, which stores LZMA-compressed data.<\/p>\n<p style=\"text-align: left;font-style: italic;font-weight: bold;margin-top: 10px\"><em>The file format used by the exploit kit to store compressed data<\/em><\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>Offset<\/strong><\/td>\n<td><strong>Field<\/strong><\/td>\n<\/tr>\n<tr>\n<td>0x00<\/td>\n<td>Magic number (0xBEDF00D)<\/td>\n<\/tr>\n<tr>\n<td>0x04<\/td>\n<td>Decompressed data size<\/td>\n<\/tr>\n<tr>\n<td>0x08<\/td>\n<td>LZMA-compressed data<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The decompressed data presents another container with the magic number 0xF00DBEEF. This file format is used in the exploit kit to store and retrieve files by their IDs.<\/p>\n<p style=\"text-align: left;font-style: italic;font-weight: bold;margin-top: 10px\"><em>The file format used by the exploit kit to store files<\/em><\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>Offset<\/strong><\/td>\n<td><strong>Field<\/strong><\/td>\n<\/tr>\n<tr>\n<td>0x00<\/td>\n<td>Magic number (0xF00DBEEF)<\/td>\n<\/tr>\n<tr>\n<td>0x04<\/td>\n<td>Number of entries<\/td>\n<\/tr>\n<tr>\n<td>0x08<\/td>\n<td>Entry[0].File ID<\/td>\n<\/tr>\n<tr>\n<td>0x0C<\/td>\n<td>Entry[0].Status<\/td>\n<\/tr>\n<tr>\n<td>0x10<\/td>\n<td>Entry[0].File offset<\/td>\n<\/tr>\n<tr>\n<td>0x14<\/td>\n<td>Entry[0].File size<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>We provide a description of all possible File ID values below. At this stage, when the payload gathers information about all available file packages, this container holds only one file, and its File ID is 0x70000.<\/p>\n<p>Finally, we get to the file with information about all available file packages. It starts with the magic value 0x12345678. The exploit kit uses this file format to obtain URLs and decryption keys for additional components that need to be downloaded.<\/p>\n<p style=\"text-align: left;font-style: italic;font-weight: bold;margin-top: 10px\"><em>The file format used by the exploit kit to store information about file packages<\/em><\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>Offset<\/strong><\/td>\n<td><strong>Field<\/strong><\/td>\n<\/tr>\n<tr>\n<td>0x00<\/td>\n<td>Magic number (0x12345678)<\/td>\n<\/tr>\n<tr>\n<td>0x04<\/td>\n<td>Flags<\/td>\n<\/tr>\n<tr>\n<td>0x08<\/td>\n<td>Directory path<\/td>\n<\/tr>\n<tr>\n<td>0x108<\/td>\n<td>Number of entries<\/td>\n<\/tr>\n<tr>\n<td>0x10C<\/td>\n<td>Entry[0].Package ID<\/td>\n<\/tr>\n<tr>\n<td>0x110<\/td>\n<td>Entry[0].ChaCha20 key<\/td>\n<\/tr>\n<tr>\n<td>0x130<\/td>\n<td>Entry[0].File name<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The components required for exploiting a targeted device are selected using the Package ID. Its high byte specifies the package type and required hardware. We\u2019ve seen the following package types:<\/p>\n<ul>\n<li>0xF2 \u2013 exploit for ARM64,<\/li>\n<li>0xF3 \u2013 exploit for ARM64E,<\/li>\n<li>0xA2 \u2013 Mach-O loader for ARM64,<\/li>\n<li>0xA3 \u2013 Mach-O loader for ARM64E,<\/li>\n<li>2 \u2013 implant for ARM64,<\/li>\n<li>0xE2 \u2013 implant for ARM64E.<\/li>\n<\/ul>\n<p>The payload code also supports additional package types, such as 0xF1, an exploit for older ARM devices that do not support 64-bit architecture. Interestingly, however, the files for such exploits are missing.<\/p>\n<p>Other bytes of the Package ID define the supported firmware version and CPU generation.<\/p>\n<p style=\"text-align: left;font-style: italic;font-weight: bold;margin-top: 10px\"><em>Some of the observed Package IDs (those with unique content)<\/em><\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>Package ID<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr>\n<td>0xF3300000<\/td>\n<td>Kernel exploit (iOS &lt; 14.0 beta 7) and other components<\/td>\n<\/tr>\n<tr>\n<td>0xF3400000<\/td>\n<td>Kernel exploit (iOS &lt; 14.7) and other components<\/td>\n<\/tr>\n<tr>\n<td>0xF3700000<\/td>\n<td>Kernel exploit (iOS &lt; 16.5 beta 4) and other components<\/td>\n<\/tr>\n<tr>\n<td>0xF3800000<\/td>\n<td>Kernel exploit (iOS &lt; 16.6 beta 5) and other components<\/td>\n<\/tr>\n<tr>\n<td>0xF3900000<\/td>\n<td>Kernel exploit (iOS &lt; 17.2) and other components<\/td>\n<\/tr>\n<tr>\n<td>0xA3030000<\/td>\n<td>Mach-O loader (iOS 16.X) (A13 \u2013 A16)<\/td>\n<\/tr>\n<tr>\n<td>0xA3050000<\/td>\n<td>Mach-O loader (iOS 16.0 \u2013 16.4)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The files inside these packages are also stored in encrypted and compressed 0xF00DBEEF containers, but this time compression is optional and is determined by the second bit in the Flags field. Different packages contain different sets of files. A description of all possible File IDs is given in the table below.<\/p>\n<p style=\"text-align: left;font-style: italic;font-weight: bold;margin-top: 10px\"><em>Observed File IDs<\/em><\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>File ID<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr>\n<td>0x10000<\/td>\n<td>Implant<\/td>\n<\/tr>\n<tr>\n<td>0x50000<\/td>\n<td>Mach-O loader (default)<\/td>\n<\/tr>\n<tr>\n<td>0x70000<\/td>\n<td>List of additional components<\/td>\n<\/tr>\n<tr>\n<td>0x70005<\/td>\n<td>Launcher config<\/td>\n<\/tr>\n<tr>\n<td>0x80000<\/td>\n<td>Launcher in 0xF2\/0xF3 packages, or Mach-O loader in 0xA2\/0xA3<\/td>\n<\/tr>\n<tr>\n<td>0x90000<\/td>\n<td>Kernel exploit<\/td>\n<\/tr>\n<tr>\n<td>0x90001<\/td>\n<td>Kernel exploit (for Mach-O loader)<\/td>\n<\/tr>\n<tr>\n<td>0xA0000<\/td>\n<td>Logs cleaner<\/td>\n<\/tr>\n<tr>\n<td>0xA0001<\/td>\n<td>Mach-O loader component<\/td>\n<\/tr>\n<tr>\n<td>0xA0002<\/td>\n<td>Mach-O loader component<\/td>\n<\/tr>\n<tr>\n<td>0xF0000<\/td>\n<td>RPC stager<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>After downloading the necessary components, the payload begins executing kernel exploits, Mach-O loaders, and the malware launcher. The payload selects an appropriate Mach-O loader based on the firmware version, CPU, and presence of the iokit-open-service permission.<\/p>\n<h3 id=\"kernel-exploits\">Kernel exploits<\/h3>\n<p>We analyzed all five kernel exploits from the kit and discovered that one of them is an updated version of the same exploit we discovered in Operation Triangulation. There are many small changes, but the most noticeable are as follows:<\/p>\n<ul>\n<li>The code takes into account more values \u200b\u200bfrom XNU version strings, allowing for more accurate version checking.<\/li>\n<li>Added a check for iOS 17.2. We assume that this was the latest version of iOS at the time of development (released in December 2023).<\/li>\n<li>Added checks for newer Apple processors: A17, M3, M3 Pro, M3 Max (released in fall 2023).<\/li>\n<li>Added a check for iOS version 16.5 beta 4. This version patched the exploit after our report to Apple.<\/li>\n<\/ul>\n<p>Why does the exploit need to check for iOS 17.2 and newer CPUs if the targeted vulnerabilities were fixed in iOS 16.5 beta 4? The answer can be found by examining other exploits: they are all based on the same source code. The only difference is in the vulnerabilities they exploit, so these checks were added to support the newer exploits and appeared in the older version after recompilation.<\/p>\n<h3 id=\"launcher\">Launcher<\/h3>\n<p>The launcher is responsible for orchestrating the post-exploitation activities. It also uses the kernel exploit and the interface it provides. However, since the exploit creates special kernel objects during its execution that provide the ability to read and write to kernel memory, the launcher simply reuses these objects without the need to trigger vulnerabilities and go through the entire exploitation path again. The launcher cleans up exploitation artifacts, retrieves the process name for injection from a config with the 0xDEADD00F magic number, injects a stager into the target process, uses it to execute itself, and launches the implant.<\/p>\n<h2 id=\"conclusions\">Conclusions<\/h2>\n<p>This case demonstrates once again the dangers associated with such malicious tools that lie in their potential wide usage. Originally developed for cyber-espionage purposes, this framework is now being used by cybercriminals of a broader kind, placing millions of users with unpatched devices at risk. Given its modular design and ease of reuse, we expect that other threat actors will begin incorporating it into their attacks. We strongly recommend that users install the latest security updates as soon as possible, if they have not already done so.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Introduction On March 4, 2026, Google and iVerify published reports about a highly sophisticated exploit kit targeting Apple iPhone devices. According to Google, the exploit kit was first discovered in targeted attacks conducted by a customer of an unnamed surveillance vendor. It was later used by other attackers in watering-hole attacks in Ukraine and in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-container-style":"default","site-container-layout":"default","site-sidebar-layout":"default","disable-article-header":"default","disable-site-header":"default","disable-site-footer":"default","disable-content-area-spacing":"default","footnotes":""},"categories":[836,903,251,256,90,291,902,248,232,664,670,904,905,241,760],"tags":[91],"class_list":["post-2143","post","type-post","status-publish","format-standard","hentry","category-apple","category-apple-ios","category-apt","category-apt-targeted-attacks","category-cybersecurity","category-encryption","category-exploit-kits","category-great-research","category-malware-descriptions","category-mobile-malware","category-mobile-threats","category-safari","category-triangulation","category-vulnerabilities-and-exploits","category-zero-day-vulnerabilities","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Coruna: the framework used in Operation Triangulation - Imperative Business Ventures Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Coruna: the framework used in Operation Triangulation - Imperative Business Ventures Limited\" \/>\n<meta property=\"og:description\" content=\"Introduction On March 4, 2026, Google and iVerify published reports about a highly sophisticated exploit kit targeting Apple iPhone devices. According to Google, the exploit kit was first discovered in targeted attacks conducted by a customer of an unnamed surveillance vendor. It was later used by other attackers in watering-hole attacks in Ukraine and in [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/\" \/>\n<meta property=\"og:site_name\" content=\"Imperative Business Ventures Limited\" \/>\n<meta property=\"article:published_time\" content=\"2026-03-26T08:04:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"headline\":\"Coruna: the framework used in Operation Triangulation\",\"datePublished\":\"2026-03-26T08:04:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/\"},\"wordCount\":1528,\"image\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Apple\",\"Apple iOS\",\"APT\",\"APT (Targeted attacks)\",\"Cybersecurity\",\"encryption\",\"Exploit Kits\",\"GReAT research\",\"Malware descriptions\",\"Mobile Malware\",\"Mobile threats\",\"Safari\",\"Triangulation\",\"Vulnerabilities and exploits\",\"Zero-day vulnerabilities\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/\",\"url\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/\",\"name\":\"Coruna: the framework used in Operation Triangulation - Imperative Business Ventures Limited\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg\",\"datePublished\":\"2026-03-26T08:04:31+00:00\",\"author\":{\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#primaryimage\",\"url\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg\",\"contentUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.ibvl.in\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Coruna: the framework used in Operation Triangulation\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.ibvl.in\/#website\",\"url\":\"https:\/\/blog.ibvl.in\/\",\"name\":\"Imperative Business Ventures Limited\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.ibvl.in\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/blog.ibvl.in\"],\"url\":\"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Coruna: the framework used in Operation Triangulation - Imperative Business Ventures Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/","og_locale":"en_US","og_type":"article","og_title":"Coruna: the framework used in Operation Triangulation - Imperative Business Ventures Limited","og_description":"Introduction On March 4, 2026, Google and iVerify published reports about a highly sophisticated exploit kit targeting Apple iPhone devices. According to Google, the exploit kit was first discovered in targeted attacks conducted by a customer of an unnamed surveillance vendor. It was later used by other attackers in watering-hole attacks in Ukraine and in [&hellip;]","og_url":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/","og_site_name":"Imperative Business Ventures Limited","article_published_time":"2026-03-26T08:04:31+00:00","og_image":[{"url":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg","type":"","width":"","height":""}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#article","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/"},"author":{"name":"admin","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"headline":"Coruna: the framework used in Operation Triangulation","datePublished":"2026-03-26T08:04:31+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/"},"wordCount":1528,"image":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#primaryimage"},"thumbnailUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg","keywords":["Cybersecurity"],"articleSection":["Apple","Apple iOS","APT","APT (Targeted attacks)","Cybersecurity","encryption","Exploit Kits","GReAT research","Malware descriptions","Mobile Malware","Mobile threats","Safari","Triangulation","Vulnerabilities and exploits","Zero-day vulnerabilities"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/","url":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/","name":"Coruna: the framework used in Operation Triangulation - Imperative Business Ventures Limited","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#primaryimage"},"image":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#primaryimage"},"thumbnailUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg","datePublished":"2026-03-26T08:04:31+00:00","author":{"@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"breadcrumb":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#primaryimage","url":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg","contentUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/03\/25105135\/coruna-featured-image-990x400.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/03\/26\/coruna-the-framework-used-in-operation-triangulation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.ibvl.in\/"},{"@type":"ListItem","position":2,"name":"Coruna: the framework used in Operation Triangulation"}]},{"@type":"WebSite","@id":"https:\/\/blog.ibvl.in\/#website","url":"https:\/\/blog.ibvl.in\/","name":"Imperative Business Ventures Limited","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.ibvl.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/blog.ibvl.in"],"url":"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/2143","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/comments?post=2143"}],"version-history":[{"count":0,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/2143\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/media?parent=2143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/categories?post=2143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/tags?post=2143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}