Coruna: a US state toolkit, fallen into Russian cybercriminals' hands
Coruna exploits 23 iOS 13 to 17.2.1 flaws, installs silently. Already in Russian criminals' hands. Activate Lockdown Mode now.
Late March 2026, we learn of Coruna. An iOS toolkit capable of silently hacking an iPhone via a simple website. Developed by a U.S. government contractor, sold to a Russian broker, exploited for four years.
It’s the first documented mass attack on Apple devices.
What’s Happening
On March 3, 2026, Google Threat Intelligence Group and iVerify published their findings. Coruna contains 23 exploits organized into five attack chains, targeting iOS 13 to 17.2.1: code execution via WebKit, PAC authentication bypass, sandbox escape, kernel privilege escalation. The kind of arsenal that costs millions to assemble.
The origin: Trenchant, the offensive division of L3Harris, a contractor for the U.S. Department of Defense. Peter Williams, its former CEO, sold eight zero-day components to Operation Zero, a Russian exploit broker, between 2022 and 2025.
The rest is mechanical. Russian intelligence (UNC6353) deploys Coruna via compromised sites targeting Ukrainians. Then Chinese cybercriminals (UNC6691) pick it up and install it on fake gambling and crypto sites. Result: 42,000 devices compromised. The first known iOS mass attack.
Why It Matters to You
Coruna isn’t just another malware. It’s a state tool that ended up on crypto phishing sites targeting individuals.
The kit deploys a loader, PlasmaGrid, targeting crypto wallets (MetaMask, Phantom, Exodus, BitKeep, Uniswap), siphoning BIP39 recovery phrases and sensitive texts stored in Apple Memos. Precision government work, repurposed for digital shoplifting.
If your iPhone is on iOS 17.3 or later, you’re protected, Apple fixed the 23 flaws with iOS 17.4.1. But an old iPhone on iOS 15 or 16, still-connected accounts, it’s an open door.
Lockdown Mode works. Coruna’s code explicitly checks if it’s active. If it is, it gives up. No attempt to bypass. Complete abandonment. I dive deeper in the dedicated article.
What You Need to Do
1. Update iOS on all your devices. The 23 flaws target iOS 13 to 17.2.1, anything above is patched. Apple released retroactive fixes for older devices.
2. Enable automatic updates (Settings > General > Software Update) to stay on top of critical patches.
3. Check that no suspicious configuration profiles are installed (Settings > General > VPN & Device Management).
Read: Lockdown Mode vs Coruna: The Mode That Stopped Everything
Sources
- Possible US Government iPhone Hacking Tool Leaked, Schneier on Security, April 2026
- Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack, CyberScoop, March 2026
- Spyware-grade Coruna iOS exploit kit now used in crypto theft attacks, BleepingComputer, March 2026
- Ex-L3Harris executive sentenced to 87 months, CyberScoop, February 2026
- Apple confirms iOS updates for older devices address the Coruna exploit, 9to5Mac, March 2026