logo

iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor

ID: a307f2f0-126d-56ae-8347-42ee83c91e7d

STIX ID: report--a307f2f0-126d-56ae-8347-42ee83c91e7d

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-03-10

Date Updated: 2026-04-21

Author: Abinaya

...
...

A powerful iPhone exploit toolkit called 'Coruna,' developed by L3Harris/Trenchant, was stolen by an insider and sold to a sanctioned Russian broker; the toolkit—containing 23 modules and reusing zero-day exploits tied to CVE-2023-32434 and CVE-2023-38606—was then used by UNC6353 in targeted watering‑hole attacks against Ukrainian iPhone users and later repurposed by Chinese cybercriminals to steal money and cryptocurrency.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.