Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Coruna Exploit Kit Targets iOS in Global Attacks

Coruna Exploit Kit Targets iOS in Global Attacks

Posted on March 5, 2026 By CWS

Recent investigations have uncovered a sophisticated exploit kit targeting iOS devices, known as ‘Coruna’. Initially developed for state-sponsored activities, this kit has now been repurposed for widespread cyber attacks, affecting users globally.

Discovery of Coruna

Both Google Threat Intelligence Group (GTIG) and iVerify have conducted separate analyses of this iOS threat. GTIG first identified the threat in February 2025, later revealing the kit’s name as Coruna. Independently, iVerify discovered the same exploit kit, undertaking weeks of technical analysis to understand its intricacies.

The reports from both entities describe Coruna as comprising 23 exploits across five chains aimed at iOS versions 13 through 17.2.1. GTIG emphasizes the advanced nature of these exploits, employing undisclosed techniques to bypass security measures, while iVerify notes the unprecedented mass exploitation of iOS devices.

Nation-State and Criminal Use

Initially spotted in use by a commercial surveillance vendor’s client, Coruna has been deployed in attacks by UNC6353, a suspected Russian espionage group, and later by UNC6691, a Chinese financially motivated gang. This transition reflects its evolution from a surveillance tool to a mechanism for financial theft.

The exploit kit’s complexity is evident, yet it becomes ineffective against newer iOS versions. Users are advised to update to iOS 17.3 or later, or activate Lockdown Mode for enhanced security. GTIG’s analysis revealed that Coruna disengages if it detects Lockdown Mode or private browsing.

Ongoing Threat and Mitigation

Coruna’s current focus is on cryptocurrency theft, with fake websites like a mock WEEX crypto exchange enticing users to access the site via iOS devices, triggering the exploit kit. This method identifies potential crypto wallet owners and delivers the exploit kit through stealthy iFrames.

Both GTIG and iVerify continue to investigate the exploit kit, aiming to release further findings. For now, they offer the most comprehensive understanding through combined insights. The ongoing analysis emphasizes the need for vigilance and up-to-date security measures on iOS devices.

This development underscores the necessity for users to remain informed about cybersecurity threats and adopt recommended security practices to safeguard their data.

Security Week News Tags:Apple security, Coruna, cryptocurrency theft, cyber attack, Cybercrime, Cybersecurity, exploit chains, GTIG, iOS exploit, iOS vulnerabilities, iVerify, Lockdown Mode, nation-state hacking, Spyware, Surveillance

Post navigation

Previous Post: Ransomware Groups Exploit AzCopy for Data Theft
Next Post: Urgent Chrome Update Fixes Critical Security Flaws

Related Posts

Large Interpol Cybercrime Crackdown in Africa Leads to the Arrest of Over 1,200 Suspects Large Interpol Cybercrime Crackdown in Africa Leads to the Arrest of Over 1,200 Suspects Security Week News
Cisco Fixes Critical Security Flaw in Identity Services Cisco Fixes Critical Security Flaw in Identity Services Security Week News
Sweden Identifies Pro-Russian Group in Cyberattack on Energy Plant Sweden Identifies Pro-Russian Group in Cyberattack on Energy Plant Security Week News
JetBrains Fixes Major Security Flaw in TeamCity JetBrains Fixes Major Security Flaw in TeamCity Security Week News
Lema AI Secures M to Revolutionize Third-Party Risk Lema AI Secures $24M to Revolutionize Third-Party Risk Security Week News
Microsoft Unveils Security Enhancements for Identity, Defense, Compliance Microsoft Unveils Security Enhancements for Identity, Defense, Compliance Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark