Close Menu
CryptargetsCryptargets
    What's Hot

    Tria Integrates Decibel To Bring Onchain Perpetual Trading To Its Users

    April 21, 2026

    Vantage Introduces An Enhanced App With A Seamless All-in-One Trading Experience

    April 21, 2026

    Hata Completes US$8 Million Series A Financing Led By Bybit

    April 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Tria Integrates Decibel To Bring Onchain Perpetual Trading To Its Users
    • Vantage Introduces An Enhanced App With A Seamless All-in-One Trading Experience
    • Hata Completes US$8 Million Series A Financing Led By Bybit
    • Bitmine Immersion Technologies (BMNR) Announces ETH Holdings Reach 4.976 Million Tokens, And Total Crypto And Total Cash Holdings Of $12.9 Billion
    • Unicoin Foundation Debuts, Aligning Social Impact With The Future Of Responsible Crypto
    • Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains
    • Charles Schwab, Citadel Both Mull Prediction Market Play
    • Congress on verge of making regulated dollar stablecoins act almost like digital cash
    Facebook X (Twitter) Instagram
    CryptargetsCryptargets
    Tuesday, April 21
    • Home
    • Press Release
    • Crypto Regulations
    • Trading Strategies
    • Altcoin Updates
    • Bitcoin Insights
    • Blockchain Startups
    • Market Analysis
    • NFT Innovations
    CryptargetsCryptargets
    Home»NFT Innovations

    Crypto Scams Using ‘Powerful’ iPhone Exploit Kit: Google

    adminBy adminMarch 5, 2026 NFT Innovations No Comments3 Mins Read
    Crypto Scams Using ‘Powerful’ iPhone Exploit Kit: Google
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat researchers at Google say they have uncovered a new exploit kit targeting Apple iPhone users, aimed at stealing crypto wallet seed phrases. 

    The kit, named “Coruna” by its developers, targets iPhones running iOS versions 13.0 up to 17.2.1. It has “five full iOS exploit chains and a total of 23 exploits,” including ones that were previously unknown to the public, the Google Threat Intelligence Group (GTIG) said in a report on Wednesday.

    The group said it first discovered the kit in February 2025 and has since tracked its use by a suspected Russian espionage group against Ukrainians, and later on fake Chinese crypto websites that aim to steal crypto.

    GTIG said the kit doesn’t work with the latest version of iOS and urged iPhone users to update their devices to the latest software version. If that isn’t possible, users should put the phone in “Lockdown Mode,” which Apple says can counter sophisticated attacks.

    Kit targets crypto via fake websites

    GTIG said it came across parts of an iOS exploit in February 2025 in which a customer of a surveillance company used JavaScript to fingerprint the device to deliver the appropriate exploit.

    Later that year, it found the same JavaScript framework hidden on multiple compromised Ukrainian websites that was “only delivered to selected iPhone users from a specific geolocation.”

    Source: Mandiant

    GTIG said it then found the same framework in December “on a very large set of fake Chinese websites mostly related to finance,” including one that spoofed the crypto exchange WEEX.

    When a user accesses the websites with an iOS device, the framework delivers the exploit kit and hunts for financial information, including analyzing texts containing seed phrases and keywords such as “backup phrase” or “bank account.”

    Related: ‘ClickFix’ hackers pose as VCs, hijack QuickLens in latest crypto attacks

    The kit also seeks out popular crypto apps, including Uniswap and MetaMask, to extract crypto or sensitive information.

    Coruna’s US intelligence origins debated

    GTIG did not name the customer of the surveillance company from which the exploit kit is said to have originated, but the mobile security company iVerify told WIRED it could have been built or bought by the US government.