Executive Summary
Analysis of a single Alibaba Cloud server revealed a diverse range of concurrent operations, most notably the deployment of the Coruna iOS exploit kit. The operator successfully compromised at least one iPhone running iOS 15.8.3 through a zero-click WebKit exploit chain, potentially aiming for cryptocurrency wallet theft via the PLASMAGRID module. The infrastructure also hosted a large-scale gambling SEO campaign involving over 300 doorway pages and thousands of target URLs, utilizing cloaking techniques to hide malicious intent from desktop users.
Technical artifacts demonstrate a high level of automation, including a Python-based CVE monitor and an AI-assisted penetration testing library drawing from nine open-source frameworks. The operator targeted multiple sectors globally, including education and academic research, through SQL injection and vulnerabilities in platforms like SPIP, Joomla, and Ivanti. A breach of a Chinese EdTech company was confirmed, resulting in the exposure of 69 databases and OAuth secrets.
The use of Simplified Chinese in scripts and comments suggests a Chinese-speaking environment. While no specific APT group is named, the professionalized nature of the toolkit—incorporating modern AI methodologies and rapid CVE-to-PoC conversion—poses a significant risk to organizations across Europe and Asia, particularly those utilizing the targeted web frameworks or mobile devices with outdated iOS versions.
Key Details
Threat Name
Coruna iOS Exploit Kit
Affects
SPIP Saisies plugin, Joomla Astroid Framework versions before 3.3.11, Ivanti EPMM, Linux kernel, Nginx
Adversary
—
Malware/Tools
Coruna, PLASMAGRID, Supershell, Impacket, sqlmap, proxychains4, nuclei, Gobuster, cve_monitor.py
