Google flags Coruna iOS malware targeting iPhone users and crypto apps including Uniswap and MetaMask
Google's Threat Intelligence Group has identified a new Coruna malware strain targeting iPhone users running iOS 13.0 through 17.2.1, designed to steal cryptocurrency-related data. The attack is delivered via fake Chinese financial websites launched in December 2023 that mimic crypto exchanges and banking platforms, exploiting iOS vulnerabilities when visited from affected iPhones without requiring user interaction, Google's analysis shows. Security researchers report Coruna scans device text in realtime for terms such as "seed phrase," "private key," "bank account" and "password," and can extract sensitive information from apps including Uniswap, MetaMask, banking apps and other crypto exchange tools. The malware leverages previously patched iOS flaws and does not require a jailbroken device, underscoring the need for users to install the latest iOS updates, verify financial website URLs and consider hardware wallets for significant crypto holdings.