The post Coruna Hack Targets Crypto Wallet Recovery Phrases appeared on BitcoinEthereumNews.com. Google researchers discovered Coruna exploit kit targets iPhonesThe post Coruna Hack Targets Crypto Wallet Recovery Phrases appeared on BitcoinEthereumNews.com. Google researchers discovered Coruna exploit kit targets iPhones

Coruna Hack Targets Crypto Wallet Recovery Phrases

For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com
  • Google researchers discovered Coruna exploit kit targets iPhones running iOS versions 13–17.
  • The toolkit contains 23 exploits and five full chains attacking Apple devices.
  • Hackers used compromised websites and fake crypto pages to infect targeted iPhones.

A sophisticated hacking toolkit capable of breaking into Apple iPhones has surfaced in espionage operations and financial cybercrime campaigns, showing how advanced surveillance technology can eventually spread into broader criminal use.

Researchers from Google Threat Intelligence Group say the exploit kit, internally called “Coruna,” targets iPhones running iOS versions 13.0 through 17.2.1, covering devices released between 2019 and late 2023.

The toolkit contains five complete exploit chains and 23 separate vulnerabilities, allowing attackers to break through multiple layers of Apple’s security system and take control of a device.

How the Attacks Worked

The Coruna exploit kit uses a sophisticated web-based attack. When a user visits a compromised website, hidden JavaScript code first scans the device to determine the iPhone model and operating system version.

Based on that information, the attack automatically loads the correct exploit chain.

One of the key vulnerabilities used in the attacks was CVE-2024-23222, a WebKit flaw later patched by Apple in iOS 17.3.

The exploit chain then bypasses several protections built into iOS, eventually installing a loader that communicates with remote command-and-control servers.

Related: Crypto Markets Stand Firm as Geopolitical Risk Hits Stocks and Oil

The Attack’s Unusual Journey

What makes Coruna particularly notable is how it appeared in very different cyber operations throughout 2025.

Early 2025: Surveillance Use

The first traces were discovered in February 2025, when researchers observed a customer of a commercial surveillance vendor using part of the exploit chain. The attack used a custom JavaScript framework with obfuscation techniques designed to hide the exploit code.

Mid-2025: Espionage Operations

By the summer of 2025, the same framework appeared on multiple compromised Ukrainian websites.

The malicious scripts were inserted into pages through hidden iframes, launching targeted attacks on visitors’ iPhones. Security analysts believe these operations were linked to a suspected Russian espionage group.

Late 2025: Financial Crime

Later in the year, researchers discovered the full exploit kit being deployed on hundreds of fake Chinese financial and cryptocurrency websites.

Targeting Crypto Wallets

Unlike many surveillance tools that focus on monitoring communications, the final payload of Coruna appears designed to steal financial information.

The malware scans the device for:

  • cryptocurrency recovery phrases
  • wallet backup files
  • banking details
  • sensitive text stored in Apple Notes

Despite its complexity, the exploit kit no longer works on the newest iOS versions. Security experts recommend that iPhone users update their devices immediately and enable advanced protections such as Lockdown Mode if they believe they may be targeted.

Related: Goldman Sachs CEO Says Middle East Tensions Could Pressure Crypto for Weeks

Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.

Source: https://coinedition.com/iphone-security-alert-coruna-hack-targets-crypto-wallet-recovery-phrases/

Market Opportunity
Overtake Logo
Overtake Price(TAKE)
$0.01863
$0.01863$0.01863
-1.48%
USD
Overtake (TAKE) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Three Reasons Why Pi Network (PI) Could Crash Again After Hitting a 3-Week High

Three Reasons Why Pi Network (PI) Could Crash Again After Hitting a 3-Week High

Meanwhile, some market observers believe PI could eventually explode above $1.
Share
CryptoPotato2026/03/05 23:54
Taiko Makes Chainlink Data Streams Its Official Oracle

Taiko Makes Chainlink Data Streams Its Official Oracle

The post Taiko Makes Chainlink Data Streams Its Official Oracle appeared on BitcoinEthereumNews.com. Key Notes Taiko has officially integrated Chainlink Data Streams for its Layer 2 network. The integration provides developers with high-speed market data to build advanced DeFi applications. The move aims to improve security and attract institutional adoption by using Chainlink’s established infrastructure. Taiko, an Ethereum-based ETH $4 514 24h volatility: 0.4% Market cap: $545.57 B Vol. 24h: $28.23 B Layer 2 rollup, has announced the integration of Chainlink LINK $23.26 24h volatility: 1.7% Market cap: $15.75 B Vol. 24h: $787.15 M Data Streams. The development comes as the underlying Ethereum network continues to see significant on-chain activity, including large sales from ETH whales. The partnership establishes Chainlink as the official oracle infrastructure for the network. It is designed to provide developers on the Taiko platform with reliable and high-speed market data, essential for building a wide range of decentralized finance (DeFi) applications, from complex derivatives platforms to more niche projects involving unique token governance models. According to the project’s official announcement on Sept. 17, the integration enables the creation of more advanced on-chain products that require high-quality, tamper-proof data to function securely. Taiko operates as a “based rollup,” which means it leverages Ethereum validators for transaction sequencing for strong decentralization. Boosting DeFi and Institutional Interest Oracles are fundamental services in the blockchain industry. They act as secure bridges that feed external, off-chain information to on-chain smart contracts. DeFi protocols, in particular, rely on oracles for accurate, real-time price feeds. Taiko leadership stated that using Chainlink’s infrastructure aligns with its goals. The team hopes the partnership will help attract institutional crypto investment and support the development of real-world applications, a goal that aligns with Chainlink’s broader mission to bring global data on-chain. Integrating real-world economic information is part of a broader industry trend. Just last week, Chainlink partnered with the Sei…
Share
BitcoinEthereumNews2025/09/18 03:34
Pundit Says XRP Price At $100 Is Not Insane If You Understand This

Pundit Says XRP Price At $100 Is Not Insane If You Understand This

Crypto pundit Bird has explained why an XRP price target of $100 is not “insane” when one understands what the XRP Ledger (XRPL) can do. He highlighted how the
Share
NewsBTC2026/03/06 00:30