

Active· since May 11, 2026
- 120
- days running
- 0
- relaunches
- 6,082
- EU reach
Ad copy
Almost three years ago, Kaspersky discovered that its own employees' iPhones had been attacked. This APT campaign became known as Operation Triangulation. During our research we uncovered four zero-day vulnerabilities and one of the most complex iOS attack chains ever publicly documented to date. This week, our GReAT team confirmed that the story didn't end there. After Google and iVerify reported on the Coruna exploit kit in March, our researchers analyzed its attack chain. The result: Coruna is built on the same framework as Operation Triangulation. Same codebase, actively maintained and expanded — now used not just for espionage, but in financially motivated attacks and indiscriminate watering-hole campaigns. A tool that once required nation-state resources to deploy is now accessible to a much wider range of threat actors. Millions of users with unpatched devices are at risk. Update your iOS. Read our full technical analysis
Learn more
Kaspersky GReAT experts look into the Coruna exploit kit targeting iPhones. We discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 is an updated version of the Operation Triangulation exploit.
LEARN MORELike this ad? Make it yours.
Crush rebuilds this exact creative around your product — your brand, your colors, your offer — in about a minute.







