DeFi Daily News
Tuesday, April 28, 2026
Advertisement
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos
No Result
View All Result
DeFi Daily News
No Result
View All Result
Home Markets Crypto Market

rewrite this title iPhone Users Warned: Crypto Scams Can Trigger ‘Coruna’ iOS Exploits

Jake Simmons by Jake Simmons
March 5, 2026
in Crypto Market
0 0
0
rewrite this title iPhone Users Warned: Crypto Scams Can Trigger ‘Coruna’ iOS Exploits
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on Telegram
Listen to this article


rewrite this content using a minimum of 1200 words and keep HTML tags

Google’s Threat Intelligence Group (GTIG) is warning that a “new and powerful” iOS exploit kit, dubbed Coruna by its developers has been deployed on fake finance and crypto websites designed to lure iPhone users into visiting pages that can silently deliver exploits. For crypto holders, the risk is blunt: GTIG’s analysis shows the campaigns ultimately focused on harvesting seed phrases and wallet data from popular mobile apps.

Coruna targets Apple devices running iOS 13.0 through iOS 17.2.1, bundling five full exploit chains and 23 exploits. GTIG says it recovered the kit after tracking its evolution across 2025, from early use by a customer of a commercial surveillance company, to “watering hole” attacks on compromised Ukrainian websites, and finally to broad-scale distribution via Chinese-language scam sites tied to a financially motivated actor it tracks as UNC6691.

A Crypto Lure Designed For iPhones

In the scam-wave phase, GTIG says it observed the JavaScript framework behind Coruna deployed across a “very large set” of fake Chinese websites largely themed around finance. One example cited by GTIG is a fake WEEX-branded crypto exchange page that tried to push visitors onto an iOS device—after which a hidden iFrame would be injected to deliver the exploit kit “regardless of their geolocation.”

Related Reading

The delivery mechanics matter because they blur the line between traditional phishing and outright device compromise: in GTIG’s telling, simply arriving on the booby-trapped page from a vulnerable iPhone was enough to begin the chain. The framework fingerprints the device to identify model and iOS version, then loads the appropriate WebKit remote code execution exploit and a pointer authentication (PAC) bypass.

GTIG tied one WebKit RCE it recovered to CVE-2024-23222, noting it was addressed by Apple in iOS 17.3 on Jan. 22, 2024.

At the end of the chain, GTIG says Coruna drops a stager it calls PlasmaLoader (tracked as PLASMAGRID) and describes it as focused less on classic surveillance features and more on stealing financial information. According to GTIG, the payload can decode QR codes from images stored on the device and scan text blobs for BIP39 word sequences, along with keywords such as “backup phrase” and “bank account”, including in Apple Memos, which it can then exfiltrate.

Related Reading

The payload is also modular. GTIG says it can pull down and run additional modules remotely, and that many of the identified modules are designed to hook functions and exfiltrate sensitive information from common crypto wallet apps—among them MetaMask, Trust Wallet, Uniswap’s wallet, Phantom, Exodus, and TON ecosystem wallets such as Tonkeeper.

The broader arc was also flagged by mobile security firm iVerify, which published its own findings around the same time as GTIG’s report. “And that’s exactly what happened again here, but on mobile devices. Phone OEMs do as good a job as anyone can do…”

What Crypto Users Can Do Now

Google says Coruna “is not effective against the latest version of iOS,” and urges users to update. If updating isn’t possible, GTIG recommends enabling Apple’s Lockdown Mode. GTIG also says it added the identified websites and domains to Google Safe Browsing to help reduce further exposure.

For crypto-native users, the immediate takeaway is practical: mobile wallets sit at the intersection of high-value assets and high-frequency web traffic, which makes “visit-to-compromise” campaigns uniquely dangerous. GTIG’s reporting suggests the scam funnel wasn’t just about getting victims to connect wallets, it was about getting them onto the right device, on the right iOS version, so exploitation could do the rest.

At press time, the total crypto market cap stood at $2.45 trillion.

Total crypto market cap faces the 0.786 Fib, 1-week chart | Source: TOTAL on TradingView.com

Featured image created with DALL.E, chart from TradingView.com

and include conclusion section that’s entertaining to read. do not include the title. Add a hyperlink to this website http://defi-daily.com and label it “DeFi Daily News” for more trending news articles like this



Source link

Tags: CorunaCryptoExploitsiOSiPhonerewriteScamstitleTriggerUsersWarned
ShareTweetShare
Previous Post

I’m $250,000 In Debt, Should I File Bankruptcy?

Next Post

Joe Rogan Experience #2464 – Priyanka Chopra Jonas

Next Post
Joe Rogan Experience #2464 – Priyanka Chopra Jonas

Joe Rogan Experience #2464 - Priyanka Chopra Jonas

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
  • Trending
  • Comments
  • Latest
rewrite this title How To Connect OpenClaw With Binance For Live AI Trading (2026)

rewrite this title How To Connect OpenClaw With Binance For Live AI Trading (2026)

April 24, 2026
rewrite this title Buying chip stocks is getting pricey. Traders don’t care

rewrite this title Buying chip stocks is getting pricey. Traders don’t care

April 24, 2026
rewrite this title Central Bank of Brazil: Stablecoins Dominate Over .9 Billion Crypto Purchases Registered in Q1

rewrite this title Central Bank of Brazil: Stablecoins Dominate Over $6.9 Billion Crypto Purchases Registered in Q1

April 26, 2026
rewrite this title What Are Ordinals? Bitcoin NFTs Are Gaining Significant Attention

rewrite this title What Are Ordinals? Bitcoin NFTs Are Gaining Significant Attention

June 27, 2025
rewrite this title and make it good for SEOIncome-Tax Bill 2025 vs Direct Tax Code proposals: How are they different

rewrite this title and make it good for SEOIncome-Tax Bill 2025 vs Direct Tax Code proposals: How are they different

February 12, 2025
Understanding Tariffs: A Guide by NerdWallet

Understanding Tariffs: A Guide by NerdWallet

October 7, 2024
rewrite this title with good SEO World-Renowned Analyst Predicts Death For Bitcoin’s Biggest Supporter, Here’s Who | Bitcoinist.com

rewrite this title with good SEO World-Renowned Analyst Predicts Death For Bitcoin’s Biggest Supporter, Here’s Who | Bitcoinist.com

April 28, 2026
rewrite this title and make it good for SEOBill Ackman’s Pershing Square raises  bln in US IPO, placement By Investing.com

rewrite this title and make it good for SEOBill Ackman’s Pershing Square raises $5 bln in US IPO, placement By Investing.com

April 28, 2026
rewrite this title Woman Gets 71 Months in Prison Over Bitcoin Investment Fraud Targeting Elderly Victims – Decrypt

rewrite this title Woman Gets 71 Months in Prison Over Bitcoin Investment Fraud Targeting Elderly Victims – Decrypt

April 28, 2026
Yahoo Finance Live: S&P, Nasdaq slump on OpenAI report, Iran war noise | Apr. 28, 2026

Yahoo Finance Live: S&P, Nasdaq slump on OpenAI report, Iran war noise | Apr. 28, 2026

April 28, 2026
rewrite this title PSG 5-4 Bayern Munich: Champions League holders beat Bayern in nine-goal thriller in first leg of semi-final

rewrite this title PSG 5-4 Bayern Munich: Champions League holders beat Bayern in nine-goal thriller in first leg of semi-final

April 28, 2026
rewrite this title This bank CEO let his AI clone handle an earnings call — now he’s signing an OpenAI deal

rewrite this title This bank CEO let his AI clone handle an earnings call — now he’s signing an OpenAI deal

April 28, 2026
DeFi Daily

Stay updated with DeFi Daily, your trusted source for the latest news, insights, and analysis in finance and cryptocurrency. Explore breaking news, expert analysis, market data, and educational resources to navigate the world of decentralized finance.

  • About Us
  • Blogs
  • DeFi-IRA | Learn More.
  • Advertise with Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Cryptocurrency
    • Bitcoin
    • Ethereum
    • Altcoins
    • DeFi-IRA
  • DeFi
    • NFT
    • Metaverse
    • Web 3
  • Finance
    • Business Finance
    • Personal Finance
  • Markets
    • Crypto Market
    • Stock Market
    • Analysis
  • Other News
    • World & US
    • Politics
    • Entertainment
    • Tech
    • Sports
    • Health
  • Videos

Copyright © 2024 Defi Daily.
Defi Daily is not responsible for the content of external sites.