Google Uncovers iPhone Exploit Kit Targeting Crypto Wallets

TheNewsCryptoPublished on 2026-03-05Last updated on 2026-03-05

Abstract

Google's Threat Intelligence Group (GTIG) has uncovered a sophisticated iOS exploit kit, dubbed 'Coruna,' targeting iPhone users on iOS versions 13.0 to 17.2.1. The kit, which contains five complete exploit chains and approximately 23 exploits—including previously unknown ones—aims to steal cryptocurrency wallet seed phrases and sensitive financial data. First identified in February 2025, the kit has been linked to a suspected Russian espionage group targeting Ukrainians and later to fake Chinese crypto websites impersonating platforms like WEEX. When users visit these sites on vulnerable iOS devices, the kit deploys to harvest financial information, including seed phrases and credentials from apps like MetaMask and Uniswap. GTIG advises users to update to the latest iOS version or enable Lockdown Mode to mitigate such attacks.

Google’s threat researchers reveal that they have unveiled a new exploit kit aiming at Apple iPhone users, targeted at stealing crypto wallet seed phrases. The kit, referred to as ‘Coruna’ by its developers, aims at iPhones working on iOS versions 13.0 up to 17.2.1.

It contains five complete iOS exploit chains and around 23 exploits, comprising ones that were so far unknown to the public, the Google Threat Intelligence Group (GTIG) mentioned in a report on March 4.

The group revealed that it first found the kit in February 2025 and has since traced its applications by a suspected Russian espionage group against Ukrainians and then to fake Chinese crypto websites that target the theft of crypto.

GTIG further mentioned that the kit does not run with the latest version of iOS and requested iPhone users update their devices to the latest software version. If that is not possible, users should put the phone in lockdown mode, which, according to Apple, can help in countering sophisticated attacks.

What Does GTIG Further Mention?

GTIG mentioned that it came across parts of an iOS exploit in February last year in which a consumer of a surveillance company used JavaScript to fingerprint the device to offer the correct exploit.

Further, in the same year, it found the same JavaScript framework concealed on various compromised Ukrainian websites that was solely delivered to selected iPhone users from a particular geolocation.

GTIG mentioned that it found the similar substructure in December on a very big set of fake Chinese websites often associated with finance, comprising one that spoofed the crypto exchange WEEX.

When a user has access to the website with an iOS device, the substructure gives the exploit kit and hunts for financial information, comprising analysing texts having seed phrases and keywords like ‘backup phrase’.

The kit also looks for prominent crypto apps, comprising Uniswap and MetaMask, to have crypto or sensitive information.

Highlighted Crypto News Today:

UK Reform Party Races Ahead Through Crypto Donations

TagsGoogleiPhoneWallet

Related Questions

QWhat is the name of the exploit kit targeting iPhone users, as revealed by Google's Threat Intelligence Group?

AThe exploit kit is referred to as 'Coruna' by its developers.

QWhich iOS versions are vulnerable to the 'Coruna' exploit kit?

AThe kit targets iPhones running on iOS versions 13.0 up to 17.2.1.

QWhat is the primary goal of the 'Coruna' exploit kit?

AIts primary goal is to steal crypto wallet seed phrases and sensitive financial information from users.

QHow does the exploit kit initially fingerprint a user's device?

AIt uses JavaScript to fingerprint the device in order to deliver the correct exploit.

QWhat two pieces of advice did GTIG give to iPhone users to protect themselves from this threat?

AGTIG advised users to update their devices to the latest iOS version or, if that's not possible, to enable lockdown mode to help counter sophisticated attacks.

Related Reads

Trading

Spot
Futures

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of S (S) are presented below.

活动图片