Close Menu
GlofiishGlofiish
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    GlofiishGlofiish
    Subscribe
    • Home
    • Glofiish Devices
    • Technology
    • Tech Devices
    • News
    • About
    • Privacy Policy
    • Contact Us
    • Terms Of Service
    GlofiishGlofiish
    Home » A US Government iPhone-Hacking Toolkit is Loose, Here’s Who is Using It
    News

    A US Government iPhone-Hacking Toolkit is Loose, Here’s Who is Using It

    Taylor LoweryBy Taylor LoweryJune 16, 2026No Comments5 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    When a weapon designed for one purpose ends up in the hands of people it was never intended for, a certain kind of unease sets in. That’s essentially what’s happening at the moment with a piece of iPhone-hacking software called Coruna, and those monitoring it can’t quite agree on how concerned everyone should be.

    Early this year, researchers at Google and the mobile security company iVerify spent time dissecting a hacking toolkit that, on paper, sounds almost unremarkable: five exploit chains, twenty-three vulnerabilities, all targeted at older iPhones. However, the specifics are anything but ordinary. Nothing needs to be clicked by the user. They are not required to open a dubious link or download a file. All they need to do is go to any website that has been covertly altered to provide the code. While the phone is in someone’s pocket, it is compromised.

    Coruna’s travel history sets it apart from the typical iOS malware. Google linked pieces of it to an anonymous buyer who was only identified as a “customer of a surveillance company” in February of last year. A more sophisticated version surfaced months later in what researchers believe to be a Russian espionage campaign embedded in regular website analytics code across Ukrainian sites—the kind of thing nobody thinks to check. Then, for some reason, the same underlying toolkit reappeared, but this time it was stripped of its spy mission and targeted Chinese-speaking cryptocurrency holders directly, draining wallets rather than obtaining intelligence.

    This kind of trajectory begs the obvious and unsettling question, “Who built this thing in the first place?” Rocky Cole, a cofounder of iVerify who worked for the NSA for many years before quitting government employment, is quite candid about how he interpreted the evidence. He believes that the code’s structure, native-level English comments, and overlap with an earlier campaign known as Triangulation—which Russia openly attributed to US intelligence—all suggest that it originated in the United States. However, he takes care to be cautious, pointing out that he has been out of government for too long to assert insider knowledge. He will only say, “It’s a good bet, though certainly not a sure bet,” on record.

    Cole’s observation of the craftsmanship is not unique. In contrast to the crude crypto-draining code that criminals later bolted onto it, Spencer Parker, chief product officer of iVerify, described the underlying exploit framework as remarkably polished, almost suspiciously so. Reading the analysis gives the impression that this software was impacted by two very different skill levels at two very different stages of its development. Something modular and disciplined was created by one author. Much later, someone else pieced together additions that, in contrast, appear almost amateurish.

    A US Government iPhone-Hacking Toolkit is Loose, Here’s Who is Using It
    A US Government iPhone-Hacking Toolkit is Loose, Here’s Who is Using It

    Naturally, none of this occurs in a vacuum. This story’s shape will be familiar to anyone who has followed cybersecurity for more than a few years because it has happened before. The NSA-developed Windows exploit EternalBlue, which was stolen and leaked in 2017, ultimately drove Russia’s NotPetya attack and North Korea’s WannaCry ransomware, two of the most catastrophic cyberattacks ever. Cole refers to Coruna as “the EternalBlue moment for mobile malware,” and it’s difficult to argue that this comparison is exaggerated.

    The scale is actually known with greater certainty. iVerify collaborated with a company that counts connections to the command-and-control servers responsible for the crypto-theft version of Coruna and has visibility into network traffic. They estimate that, just among Chinese-language scam websites, about 42,000 devices were compromised in that campaign. It is genuinely unclear how many more victims there are among the Ukrainian targets or where else this code has covertly traveled. Google has not responded. Apple hasn’t provided much information either.

    Additionally, there’s the question of how something this advanced could have escaped from controlled hands in the first place. Hacking tools don’t just disappear. Former government contractor Trenchant employee Peter Williams entered a guilty plea last year to selling at least eight company exploits to a Russian buyer thought to be Operation Zero, a broker later sanctioned by the Treasury Department. He received a seven-year sentence. It’s speculative as to whether Coruna went through a similar pipeline, an insider cashing out in secret. But considering how profitable the zero-day resale market has grown, it’s not unrealistic speculation.

    The underlying flaws in iOS 26 have been fixed by Apple, and Lockdown Mode is said to completely prevent the attack. Even so, it’s difficult to ignore how much of the public’s safety in this situation depends on people just updating their outdated phones—something that, according to Apple’s own statistics, a sizable portion of iPhone owners still haven’t done. The instruments that were supposed to be kept in a government vault are now unlocked. It’s no longer really an option to put them back.

    iPhone-Hacking Toolkit
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Taylor Lowery
    • Website

    Taylor Lowery is a senior editor at glofiish.com, a technology writer, and a true circuit enthusiast. She works in the tech sector, so she does more than just cover it. Taylor works for a smartphone company during the day, which gives her a firsthand look at how gadgets are designed, manufactured, promoted, and ultimately placed in people's hands.Her writing is unique because of this insider viewpoint. Taylor makes the technical connections that other writers overlook, whether she's dissecting the silicon architecture of a new flagship chipset, analyzing the implications of a significant Android update for actual users, or tracking the effects of a new AI model announcement across the mobile industry.Her editorial focus covers every aspect of the current tech stack, including smartphone software and hardware, artificial intelligence (from large language models and generative tools to on-device inference), and the broader innovation trends influencing the direction of the consumer technology sector. She is especially passionate about the nexus of AI and mobile computing, which she feels is still in its most exciting early stages.

    Related Posts

    Why the World’s Wealthiest Are Buying Up ‘Digital Real Estate’ Again

    June 16, 2026

    The Looming Crisis of ‘Digital Decay’: How We Are Losing the 21st Century

    June 16, 2026

    The Evolution (and Extinction) of the Smartphone

    June 16, 2026
    Leave A Reply Cancel Reply

    You must be logged in to post a comment.

    Lifestyle

    The ‘Dumbphone’ Renaissance: Why Gen Z is Ditching Apple for Minimalist Tech

    By Taylor LoweryJune 16, 20260

    Observing a 23-year-old explain, with genuine conviction, why she paid $300 for a phone that…

    A US Government iPhone-Hacking Toolkit is Loose, Here’s Who is Using It

    June 16, 2026

    Why the World’s Wealthiest Are Buying Up ‘Digital Real Estate’ Again

    June 16, 2026

    The Looming Crisis of ‘Digital Decay’: How We Are Losing the 21st Century

    June 16, 2026

    The Evolution (and Extinction) of the Smartphone

    June 16, 2026

    The Dark Side of the Gamification of Personal Finance Apps

    June 16, 2026

    The Psychology Behind the Infinite Scroll—and the Engineers Who Built It

    June 16, 2026

    The Terrifying Ease of Phishing in the Era of Generative AI

    June 16, 2026

    The Smartphone Wars Enter a New Era as AI Becomes the Ultimate Battleground

    June 16, 2026

    How Crowdsourced Supercomputing is Accelerating Cancer Research

    June 16, 2026
    Disclaimer

    Glofiish.com’s content, which includes market reporting, technology analysis, AI commentary, and device coverage, is solely meant for general informational and educational purposes. Nothing on this website is intended to be financial, investment, legal, or professional technology advice specific to your situation.

    We’re strongly advise all readers to seek independent professional financial advice from a qualified financial adviser before making any financial, investment, or purchasing decisions based only on information found on this website. Technology markets are unstable; product availability, cost, and performance attributes fluctuate quickly.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Glofiish Devices
    • Technology
    • Tech Devices
    • News
    • About
    • Privacy Policy
    • Contact Us
    • Terms Of Service
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.