PlasmaLoader, also tracked as PLASMAGRID, is a financially motivated post-exploitation malware used at the end of the Coruna iOS exploit chain. It has been associated with activity attributed to UNC6691, a China-linked threat actor focused on cryptocurrency theft. The malware is deployed after browser and kernel exploitation on Apple mobile devices and injects into a root-level iOS daemon to establish execution in a privileged context. Reporting also notes related targeting paths affecting Apple Safari-based exploitation workflows on iOS, with some Coruna coverage referencing Apple ecosystem targeting more broadly.
PlasmaLoader functions as a stager and modular loader for follow-on theft operations. It retrieves additional modules from command-and-control infrastructure, uses encrypted communications, and includes a fallback domain generation algorithm seeded with the string "lazarus" to maintain connectivity resilience. Observed behavior includes decoding QR codes from images, scanning device content for cryptocurrency wallet material and recovery phrases, and searching for banking and other sensitive financial information. It has been reported stealing data from multiple cryptocurrency wallet applications and exfiltrating sensitive information gathered from the compromised device.
The malware has been delivered in broad exploitation campaigns that used fake gambling and cryptocurrency-themed websites to compromise iPhone users through Safari and then deploy the final payload. Its role in these campaigns is distinctly financial rather than traditional espionage, with objectives centered on cryptocurrency wallet theft, seed phrase harvesting, and exfiltration of valuable user data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
the server sends a DOWNLOAD instruction containing the URL for dump.bin - a 2MB ARM64 DYLIB kernel exploit targeting CVE-2023-41974 (IOSurfaceRoot use-after-free).
The exploit kit contains five full iOS exploit chains and a total of 23 exploits, including CVE-2023-32434 and CVE-2023-38606, both of which were first used as zero-days in Operation Triangulation.
The exploit kit contains five full iOS exploit chains and a total of 23 exploits, including CVE-2023-32434 and CVE-2023-38606, both of which were first used as zero-days in Operation Triangulation.
The framework then loads the appropriate WebKit remote code execution (RCE) exploit based on the fingerprint data, followed by executing a pointer authentication code (PAC) bypass. The exploit in question relates to CVE-2024-23222, a type confusion bug in WebKit that was patched by Apple in January 2024 with iOS 17.3 and iPadOS 17.3 and iOS 16.7.5 and iPadOS 16.7.5.
Sparrow - CVE-2024-23225 (versions 17.0 → 17.3).
buffout - CVE-2021-30952 (versions 13 → 15.1.1) ... CISA, on March 5, 2026, added CVE-2021-30952 ... to its Known Exploited Vulnerabilities catalog following the abuse of the flaws in the Coruna exploit kit.
IronLoader - CVE-2023-32409 (versions 16.0 → 16.3.116.4.0).
Rocket - CVE-2024-23296 (versions 17.1 → 17.4).
The exploits deployed as part of the framework consisted of CVE-2024-23222, CVE-2022-48503, and CVE-2023-43000.
Some of the CVEs exploited by the kit and the corresponding iOS versions they targeted are listed below - Neutron - CVE-2020-27932 (versions 13.x).
The exploits deployed as part of the framework consisted of CVE-2024-23222, CVE-2022-48503, and CVE-2023-43000, the last of which is a use-after-free flaw in WebKit. It's worth noting that CVE-2023-43000 was addressed by Apple in iOS 16.6 and iPadOS 16.6, released in July 2023.
Dynamo - CVE-2020-27950 (versions 13.x).
Version 15.8.7 fixes CVE-2023-41974, CVE-2024-23222, CVE-2023-43000, and CVE-2023-43010... Meanwhile, version 16.7.15 patches the WebKit vulnerability CVE-2023-43010.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
STAGE 3: POST-EXPLOITATION ├─ PlasmaLoader / PLASMAGRID root-daemon stager deployed ├─ Primary C2 via hardcoded addresses ├─ Fallback DGA (seed: "lazarus", 15-char .xyz domains) └─ Final objectives: crypto theft, data exfiltration
Its final payload PlasmaLoader targets banking data, cryptocurrency wallets, and other sensitive information, using encrypted communications and a custom domain generation algorithm seeded with "lazarus."
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The starting point of the attack is when a user visits a compromised website on Safari, causing a stager to fingerprint the browser and serve the appropriate exploit based on the browser and operating system version. | it has since been leveraged by a suspected Russia-aligned nation-state actor in watering hole attacks in Ukraine
the server sends a DOWNLOAD instruction containing the URL for dump.bin ... then injected into the powerd system daemon for execution
Kernel R/W achieved → privilege escalation ... entitlement forging ... sandbox escape
At the end of the chain, a stager called PlasmaLoader injects into a root daemon and deploys a financially focused payload.
Its final payload PlasmaLoader targets banking data, cryptocurrency wallets, and other sensitive information, using encrypted communications and a custom domain generation algorithm seeded with "lazarus."
the server sends a DOWNLOAD instruction containing the URL for dump.bin ... then injected into the powerd system daemon for execution
Capture document.URL ... Capture navigator.userAgent ... Environment fingerprinting - hw.model , Corellium detection, kernel version parsing, SoC offset table selection
The malware scans for crypto wallets, backup phrases, and banking data, exfiltrating sensitive information ... DarkSword aims to extract an extensive set of personal information including credentials from the device and specifically targets a plethora of crypto wallet apps
It targets numerous cryptocurrency apps, uses encrypted communications, and falls back on a custom domain generation algorithm seeded with “lazarus” to maintain persistence.
HTTP Indicators: GET /<40-char-hex>.js ... POST / with Content-Type: application/json ... responseType: arraybuffer
UNC6691 has been observed weaponizing the exploit to deliver a stager binary codenamed PlasmaLoader (aka PLASMAGRID) that's designed to decode QR codes from images and run additional modules retrieved from an external server.
41 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data-stealing malware delivered via fake gambling and cryptocurrency websites as part of a mass exploitation campaign targeting iPhones through the Coruna exploit kit.
A stager/loader used at the end of the Coruna exploitation chain to inject into a root daemon and deploy a payload focused on stealing financial and cryptocurrency-related data.
Final payload associated with the Coruna exploit kit that targets banking data, cryptocurrency wallets, and other sensitive information, and uses encrypted communications plus a custom domain generation algorithm.
Post-exploitation stager/loader that injects into a root daemon and deploys a financially focused payload; supports loading additional modules from C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.