Google uncovers iPhone exploit kit targeting crypto wallet seed phrases

2026-3-7 11:53

Security researchers have uncovered a hacking toolkit designed to compromise Apple iPhones and steal cryptocurrency wallet data.

Threat analysts at Google say the exploit kit specifically targets crypto users by searching infected devices for wallet seed phrases and other financial information.

The tool, known as Coruna, focuses on iPhones running older versions of iOS.

According to Google Threat Intelligence Group, the kit contains several exploit chains capable of accessing sensitive information from targeted devices.

Researchers said they first identified parts of the attack infrastructure in early 2025 and later observed the exploit appearing in espionage activity as well as networks of fraudulent cryptocurrency websites designed to steal digital assets.

Exploit kit targets older iOS devices

Researchers said Coruna targets iPhones running iOS versions from 13.0 up to 17.2.1.

The framework contains five full exploit chains and a total of 23 vulnerabilities, including several previously unknown exploits.

https://twitter.com/Mandiant/status/2028938464784269632

The Google Threat Intelligence Group said the first traces of the toolkit appeared in February 2025 during an investigation involving a surveillance company customer.

Attackers used JavaScript code to fingerprint visiting devices.

This allowed them to determine whether the iPhone was vulnerable before delivering the appropriate exploit chain.

Researchers said the exploit does not function on the latest iOS versions.

They therefore advised users to install the most recent updates released by Apple or enable Lockdown Mode, a security feature designed to counter sophisticated cyber attacks.

Fake crypto websites deliver the attack

Further analysis showed the exploit framework later appeared on multiple compromised Ukrainian websites.

The malicious code was configured so that it would only be delivered to selected iPhone users located in specific geographic regions.

Researchers later identified the same framework embedded across a large network of fake Chinese websites connected to finance and cryptocurrency services.

Some of these websites impersonated legitimate platforms.

One example discovered by researchers spoofed the cryptocurrency exchange WEEX.

When an iPhone user visits one of these websites, the exploit kit is delivered to the device.

The software then scans the phone for financial information, analysing messages and stored data for seed phrases and keywords such as backup phrase or bank account.

The exploit also searches for installed cryptocurrency applications such as Uniswap and MetaMask to locate wallet data.

Espionage links first identified

Researchers said the exploit kit was initially linked to a suspected Russian espionage group targeting Ukrainian individuals.

Later investigations revealed the same infrastructure being used in campaigns involving fake crypto websites designed to steal funds.

The reuse of the exploit framework across espionage and financial attacks illustrates how sophisticated hacking infrastructure can spread between threat groups.

Origins remain disputed

The origin of the Coruna exploit kit remains unclear and is being debated among cybersecurity researchers.

Mobile security company iVerify told WIRED the toolkit may have been developed or purchased by the US government because of its complexity and development cost.

However, researchers at Kaspersky said they found no evidence showing code reuse linking Coruna to previously known US government cyber tools.

A principal security researcher told The Register that currently available reports do not support that attribution.

The post Google uncovers iPhone exploit kit targeting crypto wallet seed phrases appeared first on Invezz

origin »

Bitcoin price in Telegram @btc_price_every_hour

Atomic Wallet Coin (AWC) на Currencies.ru

$ 0.0757431 (+0.00%)
Объем 24H $0
Изменеия 24h: -1.82 %, 7d: -13.48 %
Cегодня L: $0.0757431 - H: $0.0771462
Капитализация $803.154k Rank 2016
Доступно / Всего 10.604m AWC

wallet seed phrases google crypto exploit kit

wallet seed → Результатов: 126


Фото:

Security Researchers Reveal Wallet Vulnerabilities On Stage at 35C3

In a demonstration titled “Wallet. fail,” a team of security researchers hacked into the Trezor One, Ledger Blue and Ledger Nano S. Unfortunately, it appears as if their findings were first put on display at the 35th Chaos Communication Congress (35C3) in Leipzig, Germany, rather than through accepted Responsible Disclosure practices, which would have allowed the manufacturers to patch the vulnerabilities and protect their customers from any potential attack.

2019-1-1 19:15


Фото:

John McAfee’s ‘unhackable’ cryptocurrency wallet has been hacked (again)

Remember John McAfee’s supposedly “unhackable” cryptocurrency wallet? It appears a group of researchers is about to prove the once-lauded antivirus pioneer wrong. After cracking the so-called Bitfi wallet to play legendary game DOOM on it, today the researchers were able to successfully send signed transactions with the device – that is despite the “security” mechanisms Bitfi has in place to prevent attackers from doing that.

2018-8-13 19:38


Фото:

Create an Unforgettable Wallet Seed by Building a Memory Palace

A 12 or 24-word recovery seed is the key to your cryptocurrency wallet. That’s why, upon creating it, you’re prompted to write it down and store it in a safe place. But what if you didn’t have to write it down? What if there was a virtually failsafe means of committing those words to memory, […] The post Create an Unforgettable Wallet Seed by Building a Memory Palace appeared first on Bitcoin News.

2018-8-13 14:50


Фото:

To Build Bitcoin Cash Mobile Wallet Startup Raises $600K

CoinText.io, a blockchain startup developing a way to conduct offline bitcoin cash transactions, just closed a $600,000 seed funding round, the company announced Friday. Lead by Texas-based Yeoman’s Capital, which has previously invested in Fantom, OpenGarden and tZero, the funding round will be used to develop a mobile wallet which can support bitcoin cash transactions

2018-6-30 01:46


Команда Nano Wallet выпустила версию 1.0.2 для Android-устройств

Блокчейн-стартап Nano представил криптокошелек Nano Wallet в версиях для Android-устройств в версии 1. 0. 2, а также для iOS. v1. 0. 2 of the Android wallet from @nanowalletco is in community review.

2018-6-23 22:09


Nano: уязвимость в Android-кошельке не представляла реальной опасности

Команда платформы Nano выпустила официальное заявление с инструкцией по устранению уязвимости в Android-кошельке Nano Wallet. Update on Android wallet: https://t. co/wqMQXftJpU If using Android, please still move to a new seed.

2018-6-22 15:10