Google Uncovers iPhone Exploit Kit Targeting Crypto Wallets

TheNewsCryptoОпубликовано 2026-03-05Обновлено 2026-03-05

Введение

Google's Threat Intelligence Group (GTIG) has uncovered a sophisticated iOS exploit kit, dubbed 'Coruna,' targeting iPhone users on iOS versions 13.0 to 17.2.1. The kit, which contains five complete exploit chains and approximately 23 exploits—including previously unknown ones—aims to steal cryptocurrency wallet seed phrases and sensitive financial data. First identified in February 2025, the kit has been linked to a suspected Russian espionage group targeting Ukrainians and later to fake Chinese crypto websites impersonating platforms like WEEX. When users visit these sites on vulnerable iOS devices, the kit deploys to harvest financial information, including seed phrases and credentials from apps like MetaMask and Uniswap. GTIG advises users to update to the latest iOS version or enable Lockdown Mode to mitigate such attacks.

Google’s threat researchers reveal that they have unveiled a new exploit kit aiming at Apple iPhone users, targeted at stealing crypto wallet seed phrases. The kit, referred to as ‘Coruna’ by its developers, aims at iPhones working on iOS versions 13.0 up to 17.2.1.

It contains five complete iOS exploit chains and around 23 exploits, comprising ones that were so far unknown to the public, the Google Threat Intelligence Group (GTIG) mentioned in a report on March 4.

The group revealed that it first found the kit in February 2025 and has since traced its applications by a suspected Russian espionage group against Ukrainians and then to fake Chinese crypto websites that target the theft of crypto.

GTIG further mentioned that the kit does not run with the latest version of iOS and requested iPhone users update their devices to the latest software version. If that is not possible, users should put the phone in lockdown mode, which, according to Apple, can help in countering sophisticated attacks.

What Does GTIG Further Mention?

GTIG mentioned that it came across parts of an iOS exploit in February last year in which a consumer of a surveillance company used JavaScript to fingerprint the device to offer the correct exploit.

Further, in the same year, it found the same JavaScript framework concealed on various compromised Ukrainian websites that was solely delivered to selected iPhone users from a particular geolocation.

GTIG mentioned that it found the similar substructure in December on a very big set of fake Chinese websites often associated with finance, comprising one that spoofed the crypto exchange WEEX.

When a user has access to the website with an iOS device, the substructure gives the exploit kit and hunts for financial information, comprising analysing texts having seed phrases and keywords like ‘backup phrase’.

The kit also looks for prominent crypto apps, comprising Uniswap and MetaMask, to have crypto or sensitive information.

Highlighted Crypto News Today:

UK Reform Party Races Ahead Through Crypto Donations

TagsGoogleiPhoneWallet

Связанные с этим вопросы

QWhat is the name of the exploit kit targeting iPhone users, as revealed by Google's Threat Intelligence Group?

AThe exploit kit is referred to as 'Coruna' by its developers.

QWhich iOS versions are vulnerable to the 'Coruna' exploit kit?

AThe kit targets iPhones running on iOS versions 13.0 up to 17.2.1.

QWhat is the primary goal of the 'Coruna' exploit kit?

AIts primary goal is to steal crypto wallet seed phrases and sensitive financial information from users.

QHow does the exploit kit initially fingerprint a user's device?

AIt uses JavaScript to fingerprint the device in order to deliver the correct exploit.

QWhat two pieces of advice did GTIG give to iPhone users to protect themselves from this threat?

AGTIG advised users to update their devices to the latest iOS version or, if that's not possible, to enable lockdown mode to help counter sophisticated attacks.

Похожее

The Midlife Crisis of Crypto GPs: No PMF, No Next Check from LPs

The article "The Midlife Crisis of Crypto GPs: No PMF, No Next LP Check" analyzes the shifting crypto fundraising landscape. It argues the era of selling grand visions to LPs is over; GPs must now offer products with clear Product-Market Fit (PMF). The author categorizes crypto fundraising products into three types: Primary (VC funds), Liquid (trading strategies), and CeFi/DeFi Native Yield. This summary focuses on the Primary market. Key points include: * **Market Shift:** LPs are impatient, demand immediate returns, and are skeptical of future promises. The "easy money" narrative has faded. * **GP Value Erosion:** LP learning curves have shortened (aided by AI), reducing the value of a GP's basic "crypto knowledge." Superior judgment is now rare. * **Weakened LP Motivations:** Traditional reasons for LPs to invest in crypto VC funds (capturing industry beta, gaining access, leveraging GP judgment) have weakened due to new products like ETFs and increased LP sophistication. * **Surviving in Primary:** The primary market will likely persist for: 1) large funds in endowment mandates treating it as a lottery ticket, 2) family offices/HNWIs using proprietary capital, 3) a few funds with proven recent outperformance, and 4) funds with strong ecosystem "deal-making" capabilities. * **Conclusion:** For most GPs, rebuilding trust requires starting over in a niche, demonstrating alpha-generating ability, or providing concrete value/services to LPs.

marsbit2 ч. назад

The Midlife Crisis of Crypto GPs: No PMF, No Next Check from LPs

marsbit2 ч. назад

Crypto GPs' Midlife Crisis: No PMF, No LP's Next Check

The article "The Midlife Crisis of Crypto GPs: No PMF, No LP's Next Check" analyzes the shifting crypto fundraising landscape. It argues that the era of LPs funding vague "vision" is over; GPs must now offer products with clear Product-Market Fit (PMF) to secure capital. The market has matured. LPs, disillusioned by the last cycle's failures and wary of long lock-up periods, now demand tangible, near-term returns rather than speculative narratives. The proliferation of accessible crypto ETFs and other liquid products has reduced the need for VC blind pools as an entry point. The author categorizes crypto fundraising products into three types: Primary (VC funds, with blind pools or clear pipelines), Liquid (alpha/beta, directional/market-neutral strategies), and CeFi/DeFi Native Yield (crypto-specific mechanisms like staking, farming). Focusing on the Primary market, the piece details why traditional LP rationales for investing in crypto VCs have weakened: easier beta access via ETFs, diminished "access" and "judgement" premiums as LPs build internal teams, and a widespread lack of proven superior returns from GPs. Ultimately, only specific players are likely to remain at the primary VC table: large funds with access to patient endowment capital, family offices/HNWIs investing proprietary capital, the few funds with demonstrable excess returns from the last cycle, and those with clear "deal-making" or ecosystem resource advantages. For others, the path forward is to rebuild trust by proving alpha-generation capability in a niche or providing concrete, valuable services.

链捕手3 ч. назад

Crypto GPs' Midlife Crisis: No PMF, No LP's Next Check

链捕手3 ч. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.4k просмотров всегоОпубликовано 2025.01.15Обновлено 2026.06.01

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.3k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片