Observed Signal · Mar 10, 2026 · Investigation / Attribution · Source: TechCrunch · Impact: 3/5 · Sentiment: Negative

Coruna: The Global iPhone-Hacking Toolkit Exposed

Executive Signal Summary

TechCrunch reports that a sophisticated iPhone-hacking toolkit called “Coruna,” discovered by Google in 2025, was used in global attacks against targets in Ukraine, China and elsewhere. Independent analysis by mobile-security researchers at iVerify and anonymous former employees indicates parts of Coruna likely originated in Trenchant, the offensive cyber/surveillance division of U.S. military contractor L3Harris, which sells tools to U.S. and Five Eyes customers. Coruna’s components were reused across operations: Google tied two shared exploits (Photon and Gallium) to Operation Triangulation, while U.S. prosecutors say a former Trenchant general manager, Peter Williams, sold multiple Trenchant tools to the Russian broker Operation Zero for $1.3 million; Williams was recently sentenced to seven years. Coruna targeted iPhones running iOS 13 through 17.2.1 and appears to have migrated from government-to-state actors and then to financially motivated cybercriminals.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Government-grade iPhone exploits reportedly leaked from a U.S. military contractor and reused by state and criminal actors raise cross-border security, supply‑chain and privacy risks for mobile platforms and could influence regulation, vendor vetting and device trust—material to many technology and advertising ecosystems but not a direct ad‑industry technical change.

SIGNAL RADAR

Track Apple Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Google revealed in 2025 that a 23-component iPhone-hacking toolkit named Coruna was used in global attacks.
  • Independent researchers at iVerify and two former L3Harris employees said parts of Coruna likely originated from Trenchant, L3Harris’s hacking and surveillance division.
  • Former Trenchant general manager Peter Williams admitted selling eight Trenchant hacking tools to Operation Zero for $1.3 million and was sentenced to seven years in prison.
  • Google linked Coruna exploits (including Photon and Gallium) to Operation Triangulation; Coruna was used by UNC6353 against Ukrainian targets and later by Chinese cybercriminals.
  • Coruna targeted iPhone models running iOS 13 through iOS 17.2.1 (released Sep 2019–Dec 2023).
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: TechCrunch•Published: Mar 10, 2026
Original Coverage Title: “The mystery of a globetrotting iPhone-hacking toolkit”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecurityMar 3, 2026

Government Hacking Tools Now in Criminal Hands: Coruna

Security researchers have identified a suite of iPhone hacking tools called Coruna that appears to have moved from a government customer into criminal hands. Google first detected Coruna in February 2025 during a surveillance vendor’s attempt to deploy spyware for a government client, later observing the same kit used in a Russian campaign against Ukrainian users and by a financially motivated hacker in China. iVerify reverse-engineered the tools and linked them to the U.S. government based on similarities to previously attributed tooling. Coruna can chain 23 vulnerabilities to compromise iPhones via watering-hole/malicious-link attacks and affects devices running iOS 13 through 17.2.1. The case highlights risks from leaked government exploits and a growing market for “secondhand” exploits.

Read assessment
CybersecurityMar 23, 2026

DarkSword iPhone Exploit Kit Leaked on GitHub

Researchers say a newer version of DarkSword, an advanced iPhone exploit kit, was publicly uploaded to GitHub, enabling easy reuse by attackers. Security firms iVerify, Google and Lookout report the samples are simple HTML/JavaScript that can be copied and hosted quickly and successfully target devices running iOS 18 or earlier. A security hobbyist demonstrated a successful compromise of an iPad mini on iOS 18. Apple said it is aware of the exploit and issued an emergency update on March 11 for devices that cannot run newer iOS releases, and noted up-to-date devices and Lockdown Mode are not at risk. According to Apple numbers cited, about one-quarter of active iPhones and iPads run iOS 18 or earlier — out of more than 2.5 billion active devices — leaving potentially hundreds of millions vulnerable. DarkSword was previously linked to campaigns against Ukrainian targets; the discovery follows another toolkit called Coruna.

Read assessment
SecurityMar 24, 2026

Darksword Exploit Kit Leaked, Puts Millions of iPhones at Risk

A modified version of the Darksword exploit kit has been published publicly on GitHub, lowering the technical barrier for large-scale attacks against iPhones and iPads. Security researchers uncovered a related hacking campaign in mid‑March 2026 that could target hundreds of millions of devices still running older iOS versions. The leaked package is composed of HTML and JavaScript files and includes code comments explaining exploit behavior and data exfiltration. Apple says devices running the latest updates (iOS 26.4/iPadOS 26) are protected and has issued emergency fixes for older models; users are advised to update or enable Lockdown Mode for extra protection.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.