Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Coruna Exploit Kit Targets iOS in Global Attacks

Coruna Exploit Kit Targets iOS in Global Attacks

Posted on March 5, 2026 By CWS

Recent investigations have uncovered a sophisticated exploit kit targeting iOS devices, known as ‘Coruna’. Initially developed for state-sponsored activities, this kit has now been repurposed for widespread cyber attacks, affecting users globally.

Discovery of Coruna

Both Google Threat Intelligence Group (GTIG) and iVerify have conducted separate analyses of this iOS threat. GTIG first identified the threat in February 2025, later revealing the kit’s name as Coruna. Independently, iVerify discovered the same exploit kit, undertaking weeks of technical analysis to understand its intricacies.

The reports from both entities describe Coruna as comprising 23 exploits across five chains aimed at iOS versions 13 through 17.2.1. GTIG emphasizes the advanced nature of these exploits, employing undisclosed techniques to bypass security measures, while iVerify notes the unprecedented mass exploitation of iOS devices.

Nation-State and Criminal Use

Initially spotted in use by a commercial surveillance vendor’s client, Coruna has been deployed in attacks by UNC6353, a suspected Russian espionage group, and later by UNC6691, a Chinese financially motivated gang. This transition reflects its evolution from a surveillance tool to a mechanism for financial theft.

The exploit kit’s complexity is evident, yet it becomes ineffective against newer iOS versions. Users are advised to update to iOS 17.3 or later, or activate Lockdown Mode for enhanced security. GTIG’s analysis revealed that Coruna disengages if it detects Lockdown Mode or private browsing.

Ongoing Threat and Mitigation

Coruna’s current focus is on cryptocurrency theft, with fake websites like a mock WEEX crypto exchange enticing users to access the site via iOS devices, triggering the exploit kit. This method identifies potential crypto wallet owners and delivers the exploit kit through stealthy iFrames.

Both GTIG and iVerify continue to investigate the exploit kit, aiming to release further findings. For now, they offer the most comprehensive understanding through combined insights. The ongoing analysis emphasizes the need for vigilance and up-to-date security measures on iOS devices.

This development underscores the necessity for users to remain informed about cybersecurity threats and adopt recommended security practices to safeguard their data.

Security Week News Tags:Apple security, Coruna, cryptocurrency theft, cyber attack, Cybercrime, Cybersecurity, exploit chains, GTIG, iOS exploit, iOS vulnerabilities, iVerify, Lockdown Mode, nation-state hacking, Spyware, Surveillance

Post navigation

Previous Post: Ransomware Groups Exploit AzCopy for Data Theft
Next Post: Urgent Chrome Update Fixes Critical Security Flaws

Related Posts

Victoria’s Secret Says It Will Postpone Earnings Report After Recent Security Breach Victoria’s Secret Says It Will Postpone Earnings Report After Recent Security Breach Security Week News
SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager Security Week News
FBI Warns of Deepfake Messages Impersonating Senior Officials FBI Warns of Deepfake Messages Impersonating Senior Officials Security Week News
Israeli Cybersecurity Funding Hits .4 Billion Record High Israeli Cybersecurity Funding Hits $4.4 Billion Record High Security Week News
Russian Hacking Suspect Wanted by the FBI Arrested on Thai Resort Island Russian Hacking Suspect Wanted by the FBI Arrested on Thai Resort Island Security Week News
UK’s Ransomware Payment Ban: Bold Strategy or Dangerous Gamble? UK’s Ransomware Payment Ban: Bold Strategy or Dangerous Gamble? Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Cisco Firewall Vulnerability Requires Immediate Fix
  • FBI and Europol Dismantle Cybercrime Forum LeakBase
  • Cisco Addresses Critical Security Flaws in Networking Gear
  • Europol Dismantles Major Phishing Service Linked to 64,000 Attacks
  • Urgent Chrome Update Fixes Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Cisco Firewall Vulnerability Requires Immediate Fix
  • FBI and Europol Dismantle Cybercrime Forum LeakBase
  • Cisco Addresses Critical Security Flaws in Networking Gear
  • Europol Dismantles Major Phishing Service Linked to 64,000 Attacks
  • Urgent Chrome Update Fixes Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News