Google Uncovers Coruna iOS Exploit Kit Used by Spies and Scammers
- The Coruna toolkit contains five iOS exploit chains and targets devices running iOS versions from 13 to 17.2.1.
- Suspected Russian espionage group UNC6353 and Chinese crypto scammers have utilized the toolkit.
- Security firm iVerify suggests the code may have origins linked to a U.S. intelligence contractor.
- Approximately 42,000 devices were compromised in one campaign using this exploit kit.
- Vulnerabilities targeted by Coruna have been patched in newer versions of Apple’s mobile operating system.
Google’s Threat Intelligence Group identified the Coruna exploit kit as a sophisticated tool used for espionage and financial scams targeting Apple devices. The toolkit has been associated with both Russian spies and Chinese cryptocurrency fraudsters, highlighting its widespread misuse.
The discovery underscores the importance of updating iOS devices to mitigate risks posed by such vulnerabilities, as evidenced by the compromise of thousands of devices before patches were applied.(Source)