Google Uncovers iPhone Exploit Kit Targeting Crypto Wallets

TheNewsCryptoОпубликовано 2026-03-05Обновлено 2026-03-05

Введение

Google's Threat Intelligence Group (GTIG) has uncovered a sophisticated iOS exploit kit, dubbed 'Coruna,' targeting iPhone users on iOS versions 13.0 to 17.2.1. The kit, which contains five complete exploit chains and approximately 23 exploits—including previously unknown ones—aims to steal cryptocurrency wallet seed phrases and sensitive financial data. First identified in February 2025, the kit has been linked to a suspected Russian espionage group targeting Ukrainians and later to fake Chinese crypto websites impersonating platforms like WEEX. When users visit these sites on vulnerable iOS devices, the kit deploys to harvest financial information, including seed phrases and credentials from apps like MetaMask and Uniswap. GTIG advises users to update to the latest iOS version or enable Lockdown Mode to mitigate such attacks.

Google’s threat researchers reveal that they have unveiled a new exploit kit aiming at Apple iPhone users, targeted at stealing crypto wallet seed phrases. The kit, referred to as ‘Coruna’ by its developers, aims at iPhones working on iOS versions 13.0 up to 17.2.1.

It contains five complete iOS exploit chains and around 23 exploits, comprising ones that were so far unknown to the public, the Google Threat Intelligence Group (GTIG) mentioned in a report on March 4.

The group revealed that it first found the kit in February 2025 and has since traced its applications by a suspected Russian espionage group against Ukrainians and then to fake Chinese crypto websites that target the theft of crypto.

GTIG further mentioned that the kit does not run with the latest version of iOS and requested iPhone users update their devices to the latest software version. If that is not possible, users should put the phone in lockdown mode, which, according to Apple, can help in countering sophisticated attacks.

What Does GTIG Further Mention?

GTIG mentioned that it came across parts of an iOS exploit in February last year in which a consumer of a surveillance company used JavaScript to fingerprint the device to offer the correct exploit.

Further, in the same year, it found the same JavaScript framework concealed on various compromised Ukrainian websites that was solely delivered to selected iPhone users from a particular geolocation.

GTIG mentioned that it found the similar substructure in December on a very big set of fake Chinese websites often associated with finance, comprising one that spoofed the crypto exchange WEEX.

When a user has access to the website with an iOS device, the substructure gives the exploit kit and hunts for financial information, comprising analysing texts having seed phrases and keywords like ‘backup phrase’.

The kit also looks for prominent crypto apps, comprising Uniswap and MetaMask, to have crypto or sensitive information.

Highlighted Crypto News Today:

UK Reform Party Races Ahead Through Crypto Donations

TagsGoogleiPhoneWallet

Связанные с этим вопросы

QWhat is the name of the exploit kit targeting iPhone users, as revealed by Google's Threat Intelligence Group?

AThe exploit kit is referred to as 'Coruna' by its developers.

QWhich iOS versions are vulnerable to the 'Coruna' exploit kit?

AThe kit targets iPhones running on iOS versions 13.0 up to 17.2.1.

QWhat is the primary goal of the 'Coruna' exploit kit?

AIts primary goal is to steal crypto wallet seed phrases and sensitive financial information from users.

QHow does the exploit kit initially fingerprint a user's device?

AIt uses JavaScript to fingerprint the device in order to deliver the correct exploit.

QWhat two pieces of advice did GTIG give to iPhone users to protect themselves from this threat?

AGTIG advised users to update their devices to the latest iOS version or, if that's not possible, to enable lockdown mode to help counter sophisticated attacks.

Похожее

Why Do You Always Lose Money on Polymarket? Because You're Betting on News, While the Pros Read the Rules

Why do you always lose money on Polymarket? Because you bet on news, while the pros study the rules. This article explains how top traders ("che tou") profit by meticulously analyzing market rules, not just predicting events. Polymarket, a prediction market platform, often sees disputes over event outcomes due to ambiguous rule wording. For instance, a market asking "Who will be the leader of Venezuela by the end of 2026?" was misinterpreted by many who bet on Delcy Rodríguez, assuming she held power. However, the rules specified "officially holds" as the formally appointed, sworn-in individual. Since Nicolás Maduro was still recognized as president officially, he won the market—even being in prison. To resolve such disputes, Polymarket uses a decentralized arbitration system via UMA protocol. The process involves: 1. Proposal: Anyone can propose a market outcome by staking 750 USDC, earning 5 USDC if unchallenged. 2. Dispute: A 2-hour window allows challenges with a 750 USDC stake; successful challengers earn 250 USDC. 3. Discussion: A 48-hour period on UMA Discord for evidence and debate. 4. Voting: UMA token holders vote in two 24-hour phases (blind then public). Outcomes require >65% consensus and 5M tokens voted; otherwise, four re-votes occur before Polymarket intervention. 5. Settlement: Results are final and automatic. Unlike traditional courts, Polymarket’s system lacks separation between arbitrators and stakeholders—voters often hold market positions, creating conflicts of interest. This leads to herd mentality in discussions and non-transparent outcomes without explanatory rulings, preventing precedent formation. Thus, success on Polymarket hinges on deep rule interpretation, not just event prediction, exploiting gaps between reality and contractual wording.

marsbit1 ч. назад

Why Do You Always Lose Money on Polymarket? Because You're Betting on News, While the Pros Read the Rules

marsbit1 ч. назад

DeepSeek Funding: Liang Wenfeng's 'Realist' Pivot

DeepSeek, a leading Chinese AI company, has initiated its first external funding round, aiming to raise at least $300 million at a valuation of no less than $10 billion. This move marks a significant shift from its founder Liang Wenfeng’s previous idealistic stance of rejecting external capital to maintain independence. Despite strong financial backing from its parent company, quantitative trading firm幻方量化 (Huanfang Quant), which provided an estimated $700 million in revenue in 2025 alone, DeepSeek faces mounting challenges. Key issues include a 15-month gap in major model updates, delays in its flagship V4 release, and the loss of several core researchers to competitors offering significantly higher compensation. The company is also undergoing a strategic pivot by migrating its infrastructure from NVIDIA’s CUDA to Huawei’s Ascend platform, a move aligned with China’s push for technological self-reliance amid U.S. export controls. However, DeepSeek lags behind rivals like智谱AI and MiniMax—both now publicly listed—in areas such as product ecosystem, multimodal capabilities, and commercialization. The funding round, though relatively small in scale, is seen as a way to establish a market-validated valuation anchor, making employee stock options more competitive and facilitating talent retention. It also signals DeepSeek’s transition from a pure research-oriented organization to a commercially-driven player in the global AI ecosystem.

marsbit2 ч. назад

DeepSeek Funding: Liang Wenfeng's 'Realist' Pivot

marsbit2 ч. назад

Торговля

Спот
Фьючерсы

Популярные статьи

Как купить S

Добро пожаловать на HTX.com! Мы сделали приобретение Sonic (S) простым и удобным. Следуйте нашему пошаговому руководству и отправляйтесь в свое крипто-путешествие.Шаг 1: Создайте аккаунт на HTXИспользуйте свой адрес электронной почты или номер телефона, чтобы зарегистрироваться и бесплатно создать аккаунт на HTX. Пройдите удобную регистрацию и откройте для себя весь функционал.Создать аккаунтШаг 2: Перейдите в Купить криптовалюту и выберите свой способ оплатыКредитная/Дебетовая Карта: Используйте свою карту Visa или Mastercard для мгновенной покупки Sonic (S).Баланс: Используйте средства с баланса вашего аккаунта HTX для простой торговли.Третьи Лица: Мы добавили популярные способы оплаты, такие как Google Pay и Apple Pay, для повышения удобства.P2P: Торгуйте напрямую с другими пользователями на HTX.Внебиржевая Торговля (OTC): Мы предлагаем индивидуальные услуги и конкурентоспособные обменные курсы для трейдеров.Шаг 3: Хранение Sonic (S)После приобретения вами Sonic (S) храните их в своем аккаунте на HTX. В качестве альтернативы вы можете отправить их куда-либо с помощью перевода в блокчейне или использовать для торговли с другими криптовалютами.Шаг 4: Торговля Sonic (S)С легкостью торгуйте Sonic (S) на спотовом рынке HTX. Просто зайдите в свой аккаунт, выберите торговую пару, совершайте сделки и следите за ними в режиме реального времени. Мы предлагаем удобный интерфейс как для начинающих, так и для опытных трейдеров.

1.1k просмотров всегоОпубликовано 2025.01.15Обновлено 2025.03.21

Как купить S

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

Он решает проблемы масштабируемости, совместимости между блокчейнами и стимулов для разработчиков с помощью технологических инноваций.

2.2k просмотров всегоОпубликовано 2025.04.09Обновлено 2025.04.09

Sonic: Обновления под руководством Андре Кронье – новая звезда Layer-1 на фоне спада рынка

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

HTX Learn — ваш проводник в мир перспективных проектов, и мы запускаем специальное мероприятие "Учитесь и Зарабатывайте", посвящённое этим проектам. Наше новое направление .

1.8k просмотров всегоОпубликовано 2025.04.10Обновлено 2025.04.10

HTX Learn: Пройдите обучение по "Sonic" и разделите 1000 USDT

Обсуждения

Добро пожаловать в Сообщество HTX. Здесь вы сможете быть в курсе последних новостей о развитии платформы и получить доступ к профессиональной аналитической информации о рынке. Мнения пользователей о цене на S (S) представлены ниже.

活动图片