user-avatar
Hamza Ahmed

Coruna iOS malware targets 18 crypto wallet apps and steals seed phrases via zero-click exploit

Google's security teams identified "Coruna", a sophisticated iOS hacking toolkit that compromises iPhones through a zero-click exploit and harvests seed phrases from 18 cryptocurrency apps such as MetaMask, Exodus, Phantom, Trust Wallet and Uniswap. The malware affects devices running iOS 17.2.1 or earlier and abuses previously known espionage exploits, while Apple's iOS 17.3 update released in January 2024 and Lockdown Mode can fully block the attack. Coruna has allegedly been used by both a suspected Russian espionage group and a financially motivated group in China, illustrating a thriving secondary market for high-end cyber tools.