by

US spyware escapes and attacks Apple fanboys

A nasty iPhone cracking toolkit, dubbed Coruna, which was likely to have been designed by US spooks has gone walkabout, and Job’s Mob users are the ones paying for it.

Google researchers say Coruna is a “highly sophisticated iPhone hacking toolkit” with five full techniques that can bypass iPhone defences and silently drop malware when a victim visits a booby-trapped website. In total, it chains 23 iOS vulnerabilities.

Google says it first saw pieces of Coruna in February last year, tied to what it called a “customer of a surveillance company”, then five months later, it turned up in suspected Russian espionage. That version was tucked into a common visitor-counting component on Ukrainian websites, because nothing says subtle like hiding a crowbar in analytics code.

Then it popped up again in a straight money-grab campaign, turning up on Chinese-language crypto and gambling sites to drop malware that steals victims’ cryptocurrency. The Fruity Cargo Cult Apple has patched the exploited bugs in newer iOS versions, but tens of thousands of devices may already have been compromised, which is a cracking advert for “trust us, we fixed it”.

Google’s report does not name the original surveillance customer, which is convenient for everyone who enjoys plausible deniability. Mobile security outfit iVerify, which analysed a Coruna sample pulled from one of the infected Chinese sites, reckons it may have started life as a kit built for, or bought by, the US government.

Google and iVerify both note that Coruna shares components with “Triangulation,” the iPhone hacking operation discovered in 2023 that hit the Russian security firm Kaspersky. Moscow claimed it was the NSA at work, and Washington did not bother to respond.

iVerify cofounder Rocky Cole said: “It’s highly sophisticated, took millions of dollars to develop, and it bears the hallmarks of other modules that have been publicly attributed to the US government,”

“This is the first example we’ve seen of very likely US government tools, based on what the code is telling us, spinning out of control and being used by both our adversaries and cybercriminal groups.”

Google, for its part, says it is watching a rare exploit arsenal bounce between operators like a stolen motor, and it is now out in the wild.

Google’s report reads: “How this proliferation occurred is unclear, but suggests an active market for ‘second-hand’ zero-day exploits. Beyond these identified exploits, multiple threat actors have now acquired advanced exploitation techniques that can be reused and modified with newly identified vulnerabilities.”

 

 

Latest articles

Share

Featured articles

Hot topics

No results found.

Latest reviews