Observed Signal · Mar 3, 2026 · Security Incident · Source: TechCrunch · Impact: 4/5 · Sentiment: Negative
Government Hacking Tools Now in Criminal Hands: Coruna
Security researchers have identified a suite of iPhone hacking tools called Coruna that appears to have moved from a government customer into criminal hands. Google first detected Coruna in February 2025 during a surveillance vendor’s attempt to deploy spyware for a government client, later observing the same kit used in a Russian campaign against Ukrainian users and by a financially motivated hacker in China. iVerify reverse-engineered the tools and linked them to the U.S. government based on similarities to previously attributed tooling. Coruna can chain 23 vulnerabilities to compromise iPhones via watering-hole/malicious-link attacks and affects devices running iOS 13 through 17.2.1. The case highlights risks from leaked government exploits and a growing market for “secondhand” exploits.
A government-origin exploit framework has leaked and is being used by state and criminal actors to compromise iPhones; affects many iOS versions and highlights an emerging market for resold exploits, with implications for device security and patching.
Track Condé Nast Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Google first identified the exploit kit named Coruna in February 2025 during a surveillance vendor’s attempt to hack a phone for a government customer.
- Google observed the Coruna kit later used by a Russian espionage group targeting Ukrainian users and by a financially motivated hacker in China.
- iVerify reverse-engineered the Coruna tools and linked the kit to the U.S. government based on similarities to previously attributed tools.
- Coruna can exploit iPhones in five distinct ways by chaining together 23 vulnerabilities and affects devices running iOS 13 up to iOS 17.2.1 (released December 2023).
- The article cites precedents of leaked government tools being abused, including the NSA's EternalBlue (2017) and the prosecution and sentencing of Peter Williams for stealing and selling exploits.
Connected Companies & Entities
1 Entity mappedRelated Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Coruna: The Global iPhone-Hacking Toolkit Exposed
TechCrunch reports that a sophisticated iPhone-hacking toolkit called “Coruna,” discovered by Google in 2025, was used in global attacks against targets in Ukraine, China and elsewhere. Independent analysis by mobile-security researchers at iVerify and anonymous former employees indicates parts of Coruna likely originated in Trenchant, the offensive cyber/surveillance division of U.S. military contractor L3Harris, which sells tools to U.S. and Five Eyes customers. Coruna’s components were reused across operations: Google tied two shared exploits (Photon and Gallium) to Operation Triangulation, while U.S. prosecutors say a former Trenchant general manager, Peter Williams, sold multiple Trenchant tools to the Russian broker Operation Zero for $1.3 million; Williams was recently sentenced to seven years. Coruna targeted iPhones running iOS 13 through 17.2.1 and appears to have migrated from government-to-state actors and then to financially motivated cybercriminals.
DarkSword iPhone Exploit Kit Leaked on GitHub
Researchers say a newer version of DarkSword, an advanced iPhone exploit kit, was publicly uploaded to GitHub, enabling easy reuse by attackers. Security firms iVerify, Google and Lookout report the samples are simple HTML/JavaScript that can be copied and hosted quickly and successfully target devices running iOS 18 or earlier. A security hobbyist demonstrated a successful compromise of an iPad mini on iOS 18. Apple said it is aware of the exploit and issued an emergency update on March 11 for devices that cannot run newer iOS releases, and noted up-to-date devices and Lockdown Mode are not at risk. According to Apple numbers cited, about one-quarter of active iPhones and iPads run iOS 18 or earlier — out of more than 2.5 billion active devices — leaving potentially hundreds of millions vulnerable. DarkSword was previously linked to campaigns against Ukrainian targets; the discovery follows another toolkit called Coruna.
Darksword Exploit Kit Leaked, Puts Millions of iPhones at Risk
A modified version of the Darksword exploit kit has been published publicly on GitHub, lowering the technical barrier for large-scale attacks against iPhones and iPads. Security researchers uncovered a related hacking campaign in mid‑March 2026 that could target hundreds of millions of devices still running older iOS versions. The leaked package is composed of HTML and JavaScript files and includes code comments explaining exploit behavior and data exfiltration. Apple says devices running the latest updates (iOS 26.4/iPadOS 26) are protected and has issued emergency fixes for older models; users are advised to update or enable Lockdown Mode for extra protection.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
