|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
한때 국가 후원 스파이 활동에 사용되었던 정교한 'Coruna' 익스플로잇 킷이 이제는 정교한 피싱 웹사이트를 통해 iPhone 사용자의 암호화폐 지갑을 표적으로 삼고 있습니다.

iPhone, Crypto, Exploit Kit: A New Wave of Digital Danger
iPhone, 암호화폐, 익스플로잇 킷: 디지털 위험의 새로운 물결
In a concerning development that blurs the lines between state-sponsored surveillance and street-level thievery, a powerful iPhone exploit kit known as 'Coruna' has been repurposed for mass financial theft. Originally designed for espionage, this sophisticated toolkit is now actively targeting cryptocurrency wallets on iPhones, turning high-tech surveillance tools into instruments for draining digital fortunes.
국가가 후원하는 감시와 거리 절도 사이의 경계를 모호하게 만드는 우려스러운 개발 과정에서 'Coruna'로 알려진 강력한 iPhone 익스플로잇 킷이 대규모 금융 절도용으로 용도가 변경되었습니다. 원래 간첩을 위해 설계된 이 정교한 툴킷은 이제 iPhone의 암호화폐 지갑을 적극적으로 표적으로 삼아 첨단 감시 도구를 디지털 재산을 빼내는 도구로 바꾸고 있습니다.
From Spies to Scammers: The Coruna Evolution
스파이에서 사기꾼으로: 코루나의 진화
Google's Threat Analysis Group (TAG) has uncovered the alarming shift of the 'Coruna' exploit kit. This advanced tool exploits a staggering 23 vulnerabilities across iOS versions 13.0 through 17.2.1. Cybercriminals are now deploying Coruna to scrape BIP39 seed phrases from unsuspecting iPhone users who visit compromised gambling sites or fake cryptocurrency exchange platforms. This represents a significant escalation, effectively democratizing military-grade surveillance capabilities for financial fraudsters.
Google의 위협 분석 그룹(TAG)은 'Coruna' 익스플로잇 킷의 놀라운 변화를 발견했습니다. 이 고급 도구는 iOS 버전 13.0부터 17.2.1까지의 무려 23개 취약점을 악용합니다. 사이버 범죄자들은 이제 손상된 도박 사이트나 가짜 암호화폐 교환 플랫폼을 방문하는 의심하지 않는 iPhone 사용자로부터 BIP39 시드 문구를 긁어내기 위해 Coruna를 배포하고 있습니다. 이는 금융 사기꾼에 대한 군사급 감시 기능을 효과적으로 민주화하여 상당한 확대를 의미합니다.
How Coruna Pilfers Your Crypto
Coruna가 암호화폐를 훔치는 방법
The mechanics behind the Coruna exploit are disturbingly sophisticated. Victims are lured to malicious websites designed to mimic legitimate services, such as the WEEX exchange or obscure gambling portals. A hidden JavaScript framework silently fingerprints the visitor's device. If a vulnerable iPhone is detected, the kit deploys a WebKit remote code execution (RCE) payload, bypassing Apple's Pointer Authentication Code (PAC) protections to gain system-level access. Once inside, Coruna bypasses typical ransomware tactics and goes straight for the digital keys. It meticulously scans the file system for data related to popular self-custody wallets, hunting for cached QR code images, unencrypted notes containing backup strings, and specific application data for wallets like MetaMask and BitKeep. The ultimate goal is to steal the 12-to-24-word BIP39 mnemonic phrases that grant complete control over a user's funds, which are then exfiltrated to command-and-control servers via encrypted channels. This entire process occurs in the background, often without any user interaction or browser crash, making it particularly lethal for those managing substantial crypto portfolios on their mobile devices.
Coruna 익스플로잇의 메커니즘은 놀라울 정도로 정교합니다. 피해자는 WEEX 거래소나 알려지지 않은 도박 포털과 같이 합법적인 서비스를 모방하도록 설계된 악성 웹사이트로 유인됩니다. 숨겨진 JavaScript 프레임워크는 방문자의 장치에서 자동으로 지문을 채취합니다. 취약한 iPhone이 감지되면 이 키트는 Apple의 PAC(포인터 인증 코드) 보호를 우회하여 WebKit RCE(원격 코드 실행) 페이로드를 배포하여 시스템 수준 액세스 권한을 얻습니다. 내부로 들어가면 Coruna는 일반적인 랜섬웨어 전술을 우회하고 디지털 키를 향해 곧바로 이동합니다. 인기 있는 자기 관리 지갑과 관련된 데이터, 캐시된 QR 코드 이미지 찾기, 백업 문자열이 포함된 암호화되지 않은 메모, MetaMask 및 BitKeep과 같은 지갑에 대한 특정 애플리케이션 데이터에 대한 파일 시스템을 꼼꼼하게 스캔합니다. 궁극적인 목표는 사용자 자금에 대한 완전한 통제권을 부여하는 12~24단어 BIP39 니모닉 문구를 훔친 다음 암호화된 채널을 통해 명령 및 제어 서버로 유출하는 것입니다. 이 전체 프로세스는 사용자 상호 작용이나 브라우저 충돌 없이 백그라운드에서 발생하므로 모바일 장치에서 상당한 암호화폐 포트폴리오를 관리하는 사람들에게 특히 치명적입니다.
The Shifting Landscape of Cyber Threats
변화하는 사이버 위협 환경
TAG's analysis points to a murky underworld of
TAG의 분석은 다음과 같은 어두운 지하 세계를 지적합니다.
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































