Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

The US Spends More On ‘Defense’ Than The Next 8 Countries Combined

May 3, 2026

Bitcoin mining stocks climb in 2026 as BTC lags behind

May 3, 2026

Alex Lab hack reportedly hits SPD Bank clients after earlier $8.3M exploit

May 3, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Google warns of crypto scams using ‘new and powerful’ iPhone exploit kit
Security

Google warns of crypto scams using ‘new and powerful’ iPhone exploit kit

March 5, 2026No Comments3 Mins Read

Threat researchers at Google say they have uncovered a new exploit kit targeting Apple iPhone users, aimed at stealing crypto wallet seed phrases.

The kit, named “Coruna” by its developers, targets iPhones running iOS versions 13.0 up to 17.2.1. It has “five full iOS exploit chains and a total of 23 exploits,” including ones that were previously unknown to the public, the Google Threat Intelligence Group (GTIG) said in a report on Wednesday.

The group said it first discovered the kit in February 2025 and has since tracked its use by a suspected Russian espionage group against Ukrainians, and later on fake Chinese crypto websites that aim to steal crypto.

GTIG said the kit doesn’t work with the latest version of iOS and urged iPhone users to update their devices to the latest software version. If that isn’t possible, users should put the phone in “Lockdown Mode,” which Apple says can counter sophisticated attacks.

Kit targets crypto via fake websites

GTIG said it came across parts of an iOS exploit in February 2025 in which a customer of a surveillance company used JavaScript to fingerprint the device to deliver the appropriate exploit.

Later that year, it found the same JavaScript framework hidden on multiple compromised Ukrainian websites that was “only delivered to selected iPhone users from a specific geolocation.”

Source: Mandiant

GTIG said it then found the same framework in December “on a very large set of fake Chinese websites mostly related to finance,” including one that spoofed the crypto exchange WEEX.

When a user accesses the websites with an iOS device, the framework delivers the exploit kit and hunts for financial information, including analyzing texts containing seed phrases and keywords such as “backup phrase” or “bank account.”

See also  Ex-CEO Pleads Guilty to Defrauding Investors With ‘Cherry-Picking’ Scheme Involving Crypto Futures Contracts

Related: ‘ClickFix’ hackers pose as VCs, hijack QuickLens in latest crypto attacks

The kit also seeks out popular crypto apps, including Uniswap and MetaMask, to extract crypto or sensitive information.

Coruna’s US intelligence origins debated

GTIG did not name the customer of the surveillance company from which the exploit kit is said to have originated, but the mobile security company iVerify told WIRED it could have been built or bought by the US government.

“It’s highly sophisticated, took millions of dollars to develop, and it bears the hallmarks of other modules that have been publicly attributed to the US government,” iVerify co-founder Rocky Cole told WIRED.

“This is the first example we’ve seen of very likely US government tools — based on what the code is telling us — spinning out of control and being used by both our adversaries and cybercriminal groups.”

However, Kaspersky’s principal security researcher told The Register that the cybersecurity company saw “no evidence of actual code reuse in the published reports to support attributing Coruna to the same authors.”

Magazine: Meet the onchain crypto detectives fighting crime better than the cops

Source link

Crypto Exploit Google iPhone Kit powerful scams Warns

Related Posts

Alex Lab hack reportedly hits SPD Bank clients after earlier $8.3M exploit

May 3, 2026

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026

Crypto industry backs CLARITY Act yield compromise, pushes Senate Banking for markup

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026
Top Posts

Alpha Pulse AI Partners With ManusPay To Allow Professional Traders To Harness Crypto Trading And DeFi Applications

April 4, 2026

Shiba Inu Team Urges SHIB Army to Secure Accounts Amid Recent Hack

October 8, 2023

Osstem Implant Deepens Connection with Indian Consumers on 20th Anniversary, Expanding Presence in Oral Care Market

April 30, 2026

Type above and press Enter to search. Press Esc to cancel.