The Coruna iPhone Hacking Kitoriginally designed for government operations, is now being used by cybercriminals. In 23 exploits spread across five complete attack chains, this framework targets iPhones running iOS 13 to 17.2.1.
This is a discovery published on March 2, 2026, by the Google Threat Intelligence Group (GTIG) that confirms a long-standing fear in the cybersecurity world: offensive tools designed for states eventually fall into criminal hands. The kit, codenamed Coruna, also known as CryptoWaters, began circulating among various threat groups as early as February 2025, before reaching a financially motivated actor operating from China in December 2025.
From the Lab to the Criminal Economy
According to the Google Threat Intelligence Group, Coruna has passed through the hands of at least three distinct types of actors in less than a year: a commercial surveillance operation, a state-sponsored attacker, and then a financially motivated criminal group. This progression illustrates the existence of an active secondary market for zero-day exploits, where tools of a power normally reserved for intelligence services become available for ordinary operations. The speed of this circulation is unprecedented.
"Coruna is one of the most significant examples we've observed of sophisticated spyware-grade capabilities proliferating from commercial surveillance vendors into the hands of nation-state actors and ultimately mass-scale criminal operations," said iVerify in its report published on March 3, 2026.
An Extraordinary Technical Architecture
The Coruna framework relies on a modular JavaScript framework capable of precisely detecting the iPhone model and iOS version of the target before loading the appropriate exploit. This fingerprinting logic allows the kit to adjust its attack in real-time, making it particularly difficult to counter with generic defenses. Google indicates that the architecture is "extremely well-designed," with components naturally linked around common exploitation frameworks.
The 23 exploits cover a range of iOS versions from 13.0 to 17.2.1. Among the most significant vulnerabilities are CVE-2024-23222, a type confusion flaw in WebKit patched by Apple in January 2024 with iOS 17.3, as well as CVE-2023-32434 and CVE-2023-38606, two flaws previously used in Operation Triangulation, according to GTIG. This latter point establishes a direct technical link with offensive tools related to previous government operations.
Three Waves of Documented Attacks
GTIG has reconstructed three phases of the kit's use between early 2024 and December 2025. The first detection dates back to early 2024, in a then-unknown JavaScript framework integrated into a commercial surveillance operation. The second wave, identified in July 2025, concerns compromised Ukrainian websites in sectors such as industrial equipment, retail, and e-commerce: these sites injected a hidden iframe to deliver the kit to iPhone users located in a specific geographic area. The espionage group UNC6353, presumed to be affiliated with Russia, is held responsible for this campaign.
The third phase, detected in December 2025, marks a radical shift. A criminal group tracked as UNC6691 deployed Coruna via a network of fake Chinese websites linked to finance, without any geographical filtering this time. Any iPhone running a vulnerable iOS version, by visiting one of these sites, could be infected. This is the first mass exploitation of iOS ever documented in the public domain.
PlasmaLoader: Emptying Crypto Wallets After Intrusion
Once the iPhone is compromised, the kit deploys an implant called PlasmaLoader (also designated PLASMAGRID), designed to decode QR codes from images and execute additional modules retrieved from an external server. The primary objective is the theft of cryptocurrencies. Targeted wallets include MetaMask, Exodus, Base, Bitget Wallet, and about twenty other applications, according to GTIG's analysis.
The implant includes a domain generation algorithm using the string "lazarus" as a seed to produce fallback domains in .xyz. This mechanism ensures continuity of communications with command and control servers, even if the main domains are blocked by network operators. iVerify has also identified modules dedicated to WhatsApp and iMessage, allowing these channels to be used as a fallback communication path in case of C2 server unavailability.
Troubling Links to State Espionage
Two of the exploits integrated into Coruna, named Photon (CVE-2023-32434) and Gallium (CVE-2023-38606), are identical to those used during Operation Triangulation, according to GTIG. In June 2023, the Russian government had publicly accused the US NSA of conducting this surveillance operation targeting "several thousand" Apple devices belonging to Russian subscribers and foreign diplomats. This attribution has never been officially confirmed by Washington.
iVerify indicates that Coruna shows similarities with frameworks developed by actors affiliated with the US government. The precise identity of the kit's original designer remains unknown at this stage. The parallel with the story of EternalBlue, the NSA exploit leaked by the Shadow Brokers group and later recycled in WannaCry, is inevitable: government digital weapons have a nasty tendency to turn against their creators.
How to Protect Your iPhone
The Coruna kit integrates checks before triggering the infection: if Lockdown Mode is active on the device or if the user is browsing in private mode, the kit abandons the attack. iOS versions from 17.3 onwards are no longer vulnerable to the exploits documented in Coruna. Updating to the latest version of iOS therefore remains the most effective and immediate measure.
For users exposed to high risks, such as journalists, human rights defenders, or business leaders, enabling Lockdown Mode provides an additional layer of protection. iVerify has made its detection application free to allow everyone to check if their device shows indicators of compromise related to Coruna. The case serves as a reminder that mobile security is no longer a concern reserved for government targets: it now concerns anyone who owns an iPhone and a cryptocurrency wallet.



No comments yet — start the discussion!