{"id":11229,"date":"2026-03-10T10:03:47","date_gmt":"2026-03-10T10:03:47","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/10\/iphone-exploit-toolkit-used-by-russian-spies-likely-originated-from-u-s-contractor\/"},"modified":"2026-03-10T10:03:47","modified_gmt":"2026-03-10T10:03:47","slug":"iphone-exploit-toolkit-used-by-russian-spies-likely-originated-from-u-s-contractor","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/10\/iphone-exploit-toolkit-used-by-russian-spies-likely-originated-from-u-s-contractor\/","title":{"rendered":"iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor"},"content":{"rendered":"<p>    iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A powerful <a href=\"https:\/\/cybersecuritynews.com\/coruna-ios-exploit-kit\/\" target=\"_blank\" rel=\"noreferrer noopener\">iPhone exploit kit named \u201cCoruna,\u201d<\/a> initially created for Western intelligence by U.S. contractor L3Harris, has fallen into the hands of Russian spies and Chinese cybercriminals.\u200b<\/p>\n<p>The Coruna toolkit features 23 different hacking components designed to compromise Apple iPhones.<\/p>\n<p>Trenchant originally built it, the hacking division of U.S. military contractor L3Harris, for use by the United States and its Five Eyes intelligence allies.\u200b<\/p>\n<p>However, the toolkit leaked when Peter Williams, a former Trenchant general manager, acted as an insider threat and stole eight of the company\u2019s tools.<\/p>\n<p>From 2022 to 2025, Williams sold these exploits for $1.3 million to Operation Zero, a sanctioned Russian exploit broker.<\/p>\n<p>After acquiring the stolen tools, <a href=\"https:\/\/cybersecuritynews.com\/operation-forumtroll-apt-hackers-exploit-google-chrome-zero-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">Operation Zero allegedly resold the spyware to unauthorized users<\/a>.<\/p>\n<p>This allowed a Russian espionage group, identified by Google as UNC6353, to deploy Coruna in targeted <a href=\"https:\/\/cybersecuritynews.com\/new-watering-hole-attacking-emeditor-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">watering-hole attacks<\/a> against Ukrainian iPhone users.<\/p>\n<p>The sophisticated toolkit later changed hands again, eventually falling into the hands of Chinese cybercriminal gangs that launched broad-scale campaigns to<a href=\"https:\/\/cybersecuritynews.com\/malware-campaign-delivers-remote-access-backdoor-and-fake-metamask-wallet\/\" target=\"_blank\" rel=\"noreferrer noopener\"> steal money and cryptocurrency from unsuspecting victims<\/a>.\u200b<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-exploits-and-operation-triangulation\"><strong>Exploits and Operation Triangulation<\/strong><\/h2>\n<p>Google and security firm iVerify confirmed that Coruna targets iPhone models running iOS 13 through 17.2.1.<\/p>\n<p>The toolkit shares striking similarities with <a href=\"https:\/\/cybersecuritynews.com\/apples-imageio-zero-day\/\" target=\"_blank\" rel=\"noreferrer noopener\">Operation Triangulation, a complex iPhone hacking campaign exposed by Kaspersky<\/a> in 2023.<\/p>\n<p>Specifically, Coruna reused two major internal exploits, Photon and Gallium, which were deployed as zero-day vulnerabilities in the Triangulation attacks.<\/p>\n<p>Security researchers tied these specific Coruna exploit names to known iOS vulnerabilities.<\/p>\n<p><a href=\"https:\/\/cybersecuritynews.com\/ios-0-day-kernel-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">\u201cPhoton\u201d is linked to CVE-2023-32434<\/a> and is described as a privilege-escalation flaw involving an integer overflow in memory mapping, affecting iOS versions 14.5 to 15.7.6.<\/p>\n<p>\u201cGallium\u201d is linked to CVE-2023-38606 and is a hardware-focused weakness used to bypass <a href=\"https:\/\/cybersecuritynews.com\/landing-page-security-how-to-manage-compliance-and-improve-performance\/\" target=\"_blank\" rel=\"noreferrer noopener\">Apple\u2019s Page Protection Layer (PPL)<\/a>, affecting iOS versions spanning roughly iOS 14.x through 16.6.<\/p>\n<p><a href=\"https:\/\/techcrunch.com\/2026\/03\/09\/an-iphone-hacking-toolkit-used-by-russian-spies-likely-came-from-u-s-military-contractor\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">As noted by independent security researcher\u00a0Costin Raiu\u00a0and highlighted by\u00a0TechCrunch<\/a>, the bird-themed internal names of Coruna\u2019s modules, such as Cassowary and Sparrow, match the naming conventions of L3Harris\u2019s hacking units.<\/p>\n<p>Furthermore, Kaspersky\u2019s custom logo for Operation Triangulation closely resembles the geometric L3Harris logo, subtly hinting at the contractor\u2019s involvement.<\/p>\n<p>While the exact path the exploits took remains murky, the leak highlights the severe risks when nation-state cyberweapons fall into the criminal underground.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/iphone-exploit-toolkit-and-russian-spies\/\">iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/iphone-exploit-toolkit-and-russian-spies\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor A powerful iPhone exploit kit named \u201cCoruna,\u201d initially created for Western intelligence by U.S. contractor L3Harris, has fallen into the hands of Russian spies and Chinese cybercriminals.\u200b The Coruna toolkit features 23 different hacking components designed to compromise Apple iPhones. Trenchant originally built [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-11229","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11229"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11229"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11229\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11229"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11229"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11229"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}