Coruna iPhone Exploit Kit Turns iPhones Into Crypto Cash Machines, Targets Old iOS Versions

Coruna iPhone Exploit Kit Turns iPhones Into Crypto Cash Machines, Targets Old iOS Versions

N
News Editor 01
2026-07-23 00:05:14
Google's Threat Intelligence Group reveals Coruna (CryptoWaters), an iOS exploit kit evolving from state surveillance to crypto theft via 23 zero-click bugs and fake exchange sites.
iPhone securitycryptocurrency theftCorunawatering hole attackiOS exploit

Google Threat Intelligence Group (GTIG) has published a deep report on a dangerous iOS exploit kit codenamed Coruna (also known as CryptoWaters). Originally developed as a state-level surveillance tool linked to Russian hacker group UNC6353 for espionage against Ukrainian citizens, the kit was acquired by Chinese hacking group UNC6691 around late 2025 to early 2026 and repurposed for digital asset theft. This shift marks the commercialization of advanced spyware—from targeted intelligence gathering to large-scale looting of ordinary cryptocurrency holders.

23 Zero-Click Bugs: The Watering Hole Attack Chain

Coruna integrates 23 distinct vulnerabilities forming 5 full exploit chains, enabling highly automated and stealthy attacks. Hackers deploy watering hole attacks by compromising or setting up fake crypto exchange and financial sites, such as a counterfeit WEEX trading platform that closely mimics the official site and is promoted via SEO and paid ads. When iPhone users visit these contaminated pages, background scripts instantly check the iOS version. If the device falls within the exploitable range, a zero-click exploit triggers silently—no user interaction or download required. Some fake sites even prompt users to browse on iOS, claiming better experience, while actually targeting outdated systems.

PlasmaLoader: Extracting Wallet Keys and Screenshots

Once Coruna gains device access, the malware PlasmaLoader activates to inventory all digital assets. It scrapes static data like photos and notes, and specifically targets popular crypto wallet apps MetaMask and Uniswap, attempting to extract private keys and seed phrases. In documented cases, victims lost funds within minutes of visiting a malicious page. Because the attack compromises system-level permissions, any digital trace of private keys left on the device is collected.

Defense: Update iOS and Enable Lockdown Mode

For iPhone users, the primary defense is keeping iOS updated. For devices that cannot receive the latest patches, enabling Apple's Lockdown Mode is effective—the malware stops running when it detects this mode. While Coruna avoids incognito browsing to lower detection chances, that is only a temporary measure. As crypto values rise, maintaining software updates and security awareness remains the essential obligation of every investor.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.