i Phones targeted by 'new and powerful' malware - and "Coruna" may have been developed by the US government | Tech Radar
Overview
i Phones targeted by 'new and powerful' malware - and "Coruna" may have been developed by the US government
Coruna may have been developed by the US government
Details
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
Google researchers discover highly complex exploit kit, dubbed 'Coruna'
The kit was deployed by a surveillance software customer, before being used by Russian and Chinese threat actors
Documentation from the kit shows evidence of being developed by the US government
A highly complex exploit kit targeting i Phones has been discovered by Google Threat Intelligence Group (GTIG) researchers, which contains non-public exploitations and bypasses.
The kit, tracked as “Coruna”, was initially used in targeted attacks by a customer of an unnamed surveillance company, before also popping up in use by Russian and Chinese threat actors before the full kit could be retrieved by GTIG.
Further research by the i Verify team into the sources of the exploits contained within the kit has indicated that the kit may have been developed as a US government framework.
Apple users beware — this devious malware can hide its activity while it hijacks your camera and microphone
Dangerous new malware targets mac OS devices via Open VSX extensions - here's how to stay safe
Chinese hackers used Brickworm malware to breach critical US infrastructure
The Coruna exploit kit is not like any regular malware developed by a common or garden hacker.
The complexity of the kit, which contains 23 exploits that work in various configurations to form five full exploit chains, signifies that the kit was assembled by a nation-state. The exploit kit is also unique in that it works to compromise devices en masse, rather than the surgical target-specific nature of spyware developed by surveillance companies, with i Verify dubbing Coruna as the “first known mass i OS attack.”
The full exploit kit was retrieved by Google after a Chinese threat actor deployed the kit for use on several gambling and cryptocurrency sites. However, when analyzed by i Verify, the exploit kit contained extensive documentation written in native English. The highly organized nature of the kit’s framework also shared similarities to frameworks developed by the US government.
The final payload of the exploit kit retrieved from the Chinese threat actors was designed to access and retrieve financial information such as crypto wallets, as well as media files and sensitive personal information.
i Verify further notes that Coruna has followed a similar trajectory to spyware and exploits developed by surveillance vendors that are then sold to governments. The exploits are are deployed in the wild by the end user, such as a government agency, where they can be picked up and stolen by other threat actors and deployed.
The most notable example of this being the Eternal Blue exploit software, which utilized a zero-day exploit to compromise Microsoft devices. Eternal Blue was actively used by the US National Security Agency (NSA) for several years, with Microsoft only being notified of the zero-day after Eternal Blue was stolen.
The i Verify team added that, “Brokers can’t be trusted with these capabilities and business to business transactions over the spyware market are highly unregulated.” The Pall Mall Process - an international framework developed to address the irresponsible development and sale of spyware and surveillance software - was specifically designed to prevent the exact situation that occurred with Eternal Blue, and may have occurred with the Coruna kit.
The Coruna kit uses exploits deployed against i Phones running i OS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023). By upgrading to the latest i OS version, your device will be protected against all the exploits used in the Coruna kit.
Users who are unable to upgrade their device to the latest i OS version should place their i Phone in Lockdown Mode. To do this, take the following steps:
Users who believe their device may have been infected should consult the GTIG indicators of compromise, and i Verify’s ‘How to get rid of it’ section.
➡️ Read our full guide to the best antivirus
- Best overall: Bitdefender Total Security
- Best for families: Norton 360 with Life Lock
- Best for mobile: Mc Afee Mobile Security
Benedict has been with Tech Radar Pro for over two years, and has specialized in writing about cybersecurity, threat intelligence, and B2B security solutions. His coverage explores the critical areas of national security, including state-sponsored threat actors, APT groups, critical infrastructure, and social engineering.
Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the Centre for Security and Intelligence Studies at the University of Buckingham, providing him with a strong academic foundation for his reporting on geopolitics, threat intelligence, and cyber-warfare.
Prior to his postgraduate studies, Benedict earned a BA in Politics with Journalism, providing him with the skills to translate complex political and security issues into comprehensible copy.
You must confirm your public display name before commenting
1 There's a big Ninja air fryer sale on — 11 of the best deals on bestsellers including this 5* model that delivers 'half the footprint, double the fun'
2i Phones targeted by 'new and powerful' malware - and "Coruna" may have been developed by the US government
3DJI teases its next 'all-new dimension' drone — while a Pro version of the DJI Osmo Pocket 4 leaks online
4I upgraded to this 27-inch 1440p 180 Hz curved gaming monitor and I've never looked back — and it can now be yours for a record-low price
5‘We heard your feedback loud and clear’ — Open AI introduces new Chat GPT 5.3 Instant to ‘reduce the cringe’ for all users
Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.
© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.
Key Takeaways
-
i Phones targeted by 'new and powerful' malware - and "Coruna" may have been developed by the US government
-
Coruna may have been developed by the US government
-
When you purchase through links on our site, we may earn an affiliate commission
-
Google researchers discover highly complex exploit kit, dubbed 'Coruna'
-
The kit was deployed by a surveillance software customer, before being used by Russian and Chinese threat actors



