Sophisticated 'Coruna' exploit kit, once used for state-sponsored espionage, now targets iPhone users' crypto wallets via sophisticated phishing websites.

iPhone, Crypto, Exploit Kit: A New Wave of Digital Danger
In a concerning development that blurs the lines between state-sponsored surveillance and street-level thievery, a powerful iPhone exploit kit known as 'Coruna' has been repurposed for mass financial theft. Originally designed for espionage, this sophisticated toolkit is now actively targeting cryptocurrency wallets on iPhones, turning high-tech surveillance tools into instruments for draining digital fortunes.
From Spies to Scammers: The Coruna Evolution
Google's Threat Analysis Group (TAG) has uncovered the alarming shift of the 'Coruna' exploit kit. This advanced tool exploits a staggering 23 vulnerabilities across iOS versions 13.0 through 17.2.1. Cybercriminals are now deploying Coruna to scrape BIP39 seed phrases from unsuspecting iPhone users who visit compromised gambling sites or fake cryptocurrency exchange platforms. This represents a significant escalation, effectively democratizing military-grade surveillance capabilities for financial fraudsters.
How Coruna Pilfers Your Crypto
The mechanics behind the Coruna exploit are disturbingly sophisticated. Victims are lured to malicious websites designed to mimic legitimate services, such as the WEEX exchange or obscure gambling portals. A hidden JavaScript framework silently fingerprints the visitor's device. If a vulnerable iPhone is detected, the kit deploys a WebKit remote code execution (RCE) payload, bypassing Apple's Pointer Authentication Code (PAC) protections to gain system-level access. Once inside, Coruna bypasses typical ransomware tactics and goes straight for the digital keys. It meticulously scans the file system for data related to popular self-custody wallets, hunting for cached QR code images, unencrypted notes containing backup strings, and specific application data for wallets like MetaMask and BitKeep. The ultimate goal is to steal the 12-to-24-word BIP39 mnemonic phrases that grant complete control over a user's funds, which are then exfiltrated to command-and-control servers via encrypted channels. This entire process occurs in the background, often without any user interaction or browser crash, making it particularly lethal for those managing substantial crypto portfolios on their mobile devices.
The Shifting Landscape of Cyber Threats
TAG's analysis points to a murky underworld of
Disclaimer:info@kdj.com
The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!
If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.