PLASMAGRID is a designation associated with infrastructure used to operate the Coruna iOS exploit kit, a large-scale exploitation framework targeting Apple iPhone users. Coruna has been observed since February 2025 and has been described as comprising multiple exploit chains spanning numerous individual exploits affecting iOS 13 through 17.2.1. Activity linked to this infrastructure has included delivery through watering-hole compromises, scam and crypto-draining websites, and themed lure pages, indicating broad and opportunistic deployment rather than a single narrowly scoped campaign. PLASMAGRID-associated infrastructure has been tied to command-and-control and exploit delivery operations. Reported infrastructure traits include distinctive web-response patterns and Cloudflare-fronted hosting behavior that enabled clustering of suspected servers. Delivery activity has included dropper pages that load JavaScript components, initialize communications with backend API endpoints, and render hidden iframe content to trigger exploit delivery. Additional linked lure infrastructure has used topical themes, including Iran war-related messaging, while earlier observed operations included compromised Ukrainian websites and Chinese scam sites. The available reporting supports PLASMAGRID as an infrastructure cluster or operational label connected to exploitation and post-delivery control of Coruna rather than a clearly attributed nation-state or formally named intrusion set. The observed use cases span surveillance-related deployment, watering-hole exploitation, and financially themed scam ecosystems, so a single actor identity, origin, or dominant motivation cannot be established with high confidence from the available facts alone.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.