Google Uncovers ’Coruna’ Exploit Kit Targeting Crypto Wallets on iPhones
Google's Threat Intelligence Group has identified a sophisticated exploit kit, dubbed 'Coruna,' targeting iPhones running iOS 13 through 17.2.1. The toolkit leverages WebKit vulnerabilities and fingerprinting techniques to steal cryptocurrency wallet data, QR codes, and sensitive financial information stored in Apple Notes. Attackers have repurposed the framework for both espionage operations and large-scale cybercrime campaigns.
The exploit chain begins with a custom JavaScript framework that fingerprints devices before delivering tailored payloads. Google traced Coruna to watering-hole attacks on Ukrainian users, where compromised websites loaded malicious code via hidden iFrames. The discovery underscores the growing convergence of surveillance tools and financial cybercrime.
While no specific cryptocurrencies or exchanges were directly named in the attacks, the threat highlights systemic risks for mobile wallet users across all major chains. Apple device owners are urged to immediately update to patched iOS versions or enable Lockdown Mode as mitigation.