Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Coruna Exploit Kit Targets iOS in Global Attacks

Coruna Exploit Kit Targets iOS in Global Attacks

Posted on March 5, 2026 By CWS

Recent investigations have uncovered a sophisticated exploit kit targeting iOS devices, known as ‘Coruna’. Initially developed for state-sponsored activities, this kit has now been repurposed for widespread cyber attacks, affecting users globally.

Discovery of Coruna

Both Google Threat Intelligence Group (GTIG) and iVerify have conducted separate analyses of this iOS threat. GTIG first identified the threat in February 2025, later revealing the kit’s name as Coruna. Independently, iVerify discovered the same exploit kit, undertaking weeks of technical analysis to understand its intricacies.

The reports from both entities describe Coruna as comprising 23 exploits across five chains aimed at iOS versions 13 through 17.2.1. GTIG emphasizes the advanced nature of these exploits, employing undisclosed techniques to bypass security measures, while iVerify notes the unprecedented mass exploitation of iOS devices.

Nation-State and Criminal Use

Initially spotted in use by a commercial surveillance vendor’s client, Coruna has been deployed in attacks by UNC6353, a suspected Russian espionage group, and later by UNC6691, a Chinese financially motivated gang. This transition reflects its evolution from a surveillance tool to a mechanism for financial theft.

The exploit kit’s complexity is evident, yet it becomes ineffective against newer iOS versions. Users are advised to update to iOS 17.3 or later, or activate Lockdown Mode for enhanced security. GTIG’s analysis revealed that Coruna disengages if it detects Lockdown Mode or private browsing.

Ongoing Threat and Mitigation

Coruna’s current focus is on cryptocurrency theft, with fake websites like a mock WEEX crypto exchange enticing users to access the site via iOS devices, triggering the exploit kit. This method identifies potential crypto wallet owners and delivers the exploit kit through stealthy iFrames.

Both GTIG and iVerify continue to investigate the exploit kit, aiming to release further findings. For now, they offer the most comprehensive understanding through combined insights. The ongoing analysis emphasizes the need for vigilance and up-to-date security measures on iOS devices.

This development underscores the necessity for users to remain informed about cybersecurity threats and adopt recommended security practices to safeguard their data.

Security Week News Tags:Apple security, Coruna, cryptocurrency theft, cyber attack, Cybercrime, Cybersecurity, exploit chains, GTIG, iOS exploit, iOS vulnerabilities, iVerify, Lockdown Mode, nation-state hacking, Spyware, Surveillance

Post navigation

Previous Post: Ransomware Groups Exploit AzCopy for Data Theft
Next Post: Urgent Chrome Update Fixes Critical Security Flaws

Related Posts

Chinese Cyberattack Hits Singapore’s Telecom Sector Chinese Cyberattack Hits Singapore’s Telecom Sector Security Week News
Chrome 148 Launches with Key Security Enhancements Chrome 148 Launches with Key Security Enhancements Security Week News
Crimenetwork Crime Hub Dismantled by German Police Crimenetwork Crime Hub Dismantled by German Police Security Week News
Wytec Expects Significant Financial Loss Following Website Hack Wytec Expects Significant Financial Loss Following Website Hack Security Week News
Cisco Patches Vulnerability Exploited by Chinese Hackers Cisco Patches Vulnerability Exploited by Chinese Hackers Security Week News
Government, Industrial Servers Targeted in China-Linked ‘PassiveNeuron’ Campaign Government, Industrial Servers Targeted in China-Linked ‘PassiveNeuron’ Campaign Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Coralogix Secures $200M to Enhance AI Observability Tools
  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Coralogix Secures $200M to Enhance AI Observability Tools
  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark