/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google details Coruna, an exploit kit used to hijack iPhones via malicious websites; iVerify suggests it may have been originally built for the US government

A highly sophisticated set of iPhone hijacking techniques has likely infected tens of thousands of phones or more.

Wired Andy Greenberg

Context & Ripple Effects

Google’s prior disclosures have traced iOS compromise tools across both commercial spyware and narrowly targeted campaigns, including Hermit’s Android and iOS tooling and zero-day-driven campaigns against mobile and browser users. Coruna matters because the reported scale shifts the concern from a small set of hand-picked targets toward web-delivered iPhone compromise that may have reached a much broader population.

iVerify’s suggestion of a possible US-government origin is an assessment, not confirmed attribution. Still, it puts renewed focus on how sophisticated exploit capabilities can move beyond their original intended users or mission.

First-order effects

  • Google’s technical disclosure gives iPhone security teams and affected users a basis to investigate exposure to the malicious websites and prioritize remediation.
  • The report puts iVerify’s origin assessment under scrutiny while drawing attention to the potentially large population exposed to the kit.

Second-order effects

  • Mobile-security vendors and incident-response teams will face pressure to improve detection of web-based iPhone compromise, rather than concentrating solely on app- or device-level threats.
  • If the reported scale is borne out, organizations with high-risk iPhone users may reassess browser isolation, monitoring, and response practices for mobile fleets.

Third-order effects

  • The case reinforces a persistent asymmetry in mobile security: a small number of advanced exploit chains can create broad exposure when delivered through websites, making rapid disclosure and patch adoption more consequential.
  • If tools associated with state-grade development continue to appear in wider operations, the boundary between targeted espionage tooling and scalable commercial-style intrusion capability may keep eroding.

The trend: Coruna is part of the broader shift toward sophisticated mobile exploit chains being deployed through ordinary web access, widening the potential victim pool beyond traditionally targeted users.

Discussion

  • @lukolejnik Lukasz Olejnik on x
    Google has identified an iOS exploit kit named Coruna. 5 full exploit chains, 23 vulnerabilities, documentation in native English, modular architecture. Full professionalism. It must have cost millions of dollars. Who built it? Google doesn't say, but the evidence points to US
  • @patrickwardle Patrick Wardle on x
    A few weeks ago, Apple announce that “iPhone and iPad [are] approved to handle *classified* NATO information” 😂 Turns out even lowly cybercriminals were (ab)using 0days to hack Apple devices 🙈 https://www.wired.com/...
  • @c2iris @c2iris on x
    This was almost certainly the result of Peter Williams' traitorous conduct.
  • @vxunderground @vxunderground on x
    Yeah, so basically Mandiant and iVerify released a paper today about this spoopy thingy called “Coruna”. Coruna is very, very silly. Mandiant and iVerify discovered SOMEONE (they don't say who) developed some hardcore iOS zero day exploits. It exploited how iOS devices handled [i…
  • @_danielsinclair Daniel Sinclair on x
    In case you're wondering what Ethereum wallets are up against: Crypto thieves got their hands on a highly sophisticated NSA exploit toolkit and zero-click (iOS 13 - 17.4) and used it to deploy key stealer payloads against mobile wallets. https://cloud.google.com/...
  • @mandiant @mandiant on x
    Coruna exploit kit is targeting iOS. Coruna leverages 23 exploits against Apple devices running iOS 13-17.2.1. It is being used for espionage, and by financially motivated actors to steal crypto. Update your iOS devices, and learn more about this threat: https://cloud.google.com/…
  • @godisvoluntary @godisvoluntary on x
    More reason to keep Lockdown enabled on Apple devices.
  • @darkwebinformer @darkwebinformer on x
    ‼️ Google has uncovered a Coruna iOS exploit kit tied to U.S. origins https://cloud.google.com/... [image]
  • @a_greenberg Andy Greenberg on x
    A full iOS exploit toolkit, “Coruna,” has been found in the wild, hacking iPhones that visited infected websites, used by Russian spies targeting Ukrainians and thieves targeting Chinese crypto holders. And it may have been created for the US government. https://www.wired.com/...
  • @joparkerbear @joparkerbear on bluesky
    First of all, this is very, very bad.  —  Second, the vulnerabilities were allegedly patched in iOS 26 (according to Google), but that does not help the iPhone users who were already hacked.  —  Finally, why the FUCK am i learning about this from GOOGLE?  Show your fucking face, …
  • @ssg.dev Sedat Kapanoğlu on bluesky
    this is why encryption backdoors for government use is a terrible idea.  because once they're in place, they'll eventually be used by malicious actors.  —  > A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals
  • @couts Andrew Couts on bluesky
    NEW: Researchers at Google and @iverify.bsky.social discovered a set of iPhone-hacking techniques that has the characteristics of hacking tools made for the US gov't.  Apple patched the 23 vulnerabilities in its latest version of iOS. @agreenberg.bsky.social reports: www.wired.co…
  • r/TrueReddit r on reddit
    A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals
  • r/hacking r on reddit
    A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals
  • r/technology r on reddit
    A suite of government hacking tools targeting iPhones is now being used by cybercriminals
  • r/ios r on reddit
    A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals
  • r/iphone r on reddit
    A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals
  • r/Malware r on reddit
    A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals
  • r/blackhat r on reddit
    A Possible US Government iPhone-Hacking Toolkit Is Now in the Hands of Foreign Spies and Criminals