Coruna landing kit: platform_module.js fetch from iOS Safari client
Detects a multi-stage exploit chain targeting iOS Safari clients, characterized by the sequential fetching of specific JavaScript modules (platform_module.js, utility_module.js, Stage1, Stage3, and bootstrap.dylib) and subsequent callback communication to a remote server. This pattern is consistent with a browser-based exploit framework targeting iOS devices.
Suricata

