Connect with us

Crypto World

Google Exposes Coruna Exploit Kit Stealing Cryptocurrency from iPhone Users on iOS 13-17.2.1

Published

on

Nexo Partners with Bakkt for US Crypto Exchange and Yield Programs

Key Takeaways

  • Google’s security researchers reveal Coruna exploit framework designed to steal cryptocurrency from iPhones.
  • The exploit framework successfully compromises iOS versions 13 through 17.2.1 via WebKit vulnerabilities.
  • Multiple threat actors deploy identical exploits for both espionage campaigns and financial cybercrime.
  • Malicious code targets cryptocurrency wallets, QR codes, and stored notes containing sensitive credentials.
  • Immediate iOS updates or Lockdown Mode activation recommended for device protection.

Security researchers at Google have uncovered a sophisticated exploitation framework specifically designed to compromise iPhones operating on iOS versions ranging from 13 to 17.2.1. According to Google’s Threat Intelligence Group, cybercriminals leverage this exploit toolkit to extract cryptocurrency wallet credentials and other valuable financial data. Google’s analysis reveals that the framework has been adopted by various malicious actors conducting both state-sponsored surveillance and widespread financial fraud operations.

Google monitors Coruna exploit framework distribution among cybercriminal groups

The Threat Intelligence division at Google first encountered this exploitation toolkit while investigating targeted surveillance activities during the early months of 2025. Security analysts at Google observed threat actors utilizing the framework through specialized JavaScript code engineered to profile iPhone hardware. This profiling mechanism determines specific device models and firmware versions before deploying customized exploitation sequences.

Google subsequently traced connections between this identical exploit framework and watering-hole compromises specifically aimed at Ukrainian internet users. The malicious JavaScript appeared embedded within legitimate but compromised websites, loading through concealed iFrames that activated exclusively when visitors accessed sites using iPhones. Google’s research team attributed these intrusion attempts to UNC6353, a threat actor suspected of conducting Russian intelligence operations.

Further investigation by Google revealed the same exploitation toolkit operating across extensive networks of deceptive Chinese financial platforms. These fraudulent websites presented themselves as legitimate cryptocurrency exchanges and online gambling services to deceive potential victims. Google’s findings indicate that financially motivated cybercriminals subsequently adopted the toolkit for mass-scale criminal operations.

Google researchers document exploit sequences across multiple iOS releases

According to Google’s technical analysis, the Coruna framework encompasses five complete exploitation sequences utilizing twenty-three distinct security vulnerabilities. The toolkit successfully compromises iPhone devices operating any firmware version between iOS 13 and iOS 17.2.1. Google’s security analysts verified that attackers weaponize WebKit browser vulnerabilities as the initial attack vector to gain code execution on victim devices.

Advertisement

The exploitation framework incorporates sophisticated techniques to circumvent advanced security mechanisms including pointer authentication controls. Following successful initial compromise, attackers deliver encrypted binary components specifically crafted to inject additional malicious modules into the operating system. Google’s technical documentation describes a specialized loader component that infiltrates code directly into iOS power management system processes.

Google additionally documented that the exploit framework intentionally avoids compromising devices operating with Lockdown Mode enabled or during private browsing sessions. The toolkit employs advanced fingerprinting methodologies to confirm it exclusively targets authentic iPhone hardware. Google’s technical assessment demonstrates that attackers meticulously engineered the framework to deploy version-specific exploit sequences tailored to each target device.

Google security team identifies crypto wallet theft as primary objective

Google‘s security analysts determined that the ultimate malware payload concentrates on harvesting financial credentials and cryptocurrency information stored within compromised devices. The malware systematically scans filesystem contents and image files searching for cryptocurrency wallet recovery phrases and banking-related references. Google documented that the malicious code specifically searches for BIP39 mnemonic seed phrases and associated wallet backup terminology.

The malicious application possesses capabilities to analyze photographic content stored on compromised devices, specifically scanning for QR code patterns containing wallet credentials or transaction information. Upon successfully identifying valuable data, the malware establishes connections with attacker-operated command infrastructure to exfiltrate the stolen information. Google’s analysis confirmed the malware additionally searches Apple Notes application data for content referencing banking credentials or cryptographic recovery keys.

Advertisement

Google verified that the exploitation framework no longer successfully compromises the most recent iOS firmware releases. Nevertheless, Google strongly advises users to immediately update devices currently operating outdated operating system versions. The security team additionally recommends activating Lockdown Mode on devices where immediate updates prove impractical, significantly reducing vulnerability to similar exploitation attempts.

 

Source link

Advertisement
Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Crypto World

Revolut Files for US Bank Charter and Names Former Visa Executive Cetin Duransoy as New US CEO

Published

on

Nexo Partners with Bakkt for US Crypto Exchange and Yield Programs

TLDR:

  • Revolut has filed for a US bank charter with the OCC and FDIC to offer full banking services in America. 
  • Former Visa executive Cetin Duransoy has been named Revolut’s new CEO for United States operations. 
  • Revolut plans to invest $500 million in the US over three to five years covering capital, marketing, and hiring. 
  • Revolut’s global valuation reached $75 billion following a secondary share sale completed in November 2024.

Revolut has officially filed for a U.S. bank charter, marking a major move into the American financial market. The British fintech giant also named former Visa executive Cetin Duransoy as its new United States CEO.

With around 70 million clients across 40 markets, Revolut is targeting the U.S. as a core part of its global expansion.

The applications have been submitted to the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation for review.

Revolut Eyes US Banking Approval to Expand Financial Services

If regulators approve the applications, Revolut plans to gather deposits and issue loans in the U.S. The company also intends to offer credit cards and facilitate payments for American customers.

This would represent a full-scale banking operation, moving beyond its current limited U.S. presence. Revolut currently serves American users primarily through payment and foreign exchange services.

Advertisement

Revolut founder and CEO Nik Storonsky made the company’s intentions clear in a recent statement. “The United States is a key pillar of our global growth strategy,” Storonsky said.

He added that a stronger U.S. presence is necessary to reach 100 million global customers. The company is expected to invest $500 million in the U.S. over the next three to five years.

That $500 million figure covers bank capital, marketing, and new hiring across the country. Outgoing U.S. CEO Sid Jajodia confirmed the investment scope in a recent interview.

Jajodia will transition into a global chief banking officer role as Duransoy steps in. Duransoy’s background at Visa brings strong financial industry experience to Revolut’s U.S. operations.

Revolut’s strategy involves attracting users first as a secondary bank account. Services like payments and foreign exchange act as entry points for new customers.

Over time, the company woos users with perks and subscription-based offerings. This model has already proven effective across Europe and other international markets.

Advertisement

Revolut’s US Push Comes Amid Growing Neobank Competition

Revolut is not alone in pursuing a U.S. banking license among global neobanks. Brazil’s Nubank is currently awaiting full approval for its own U.S. banking license.

Spain’s Santander launched a digital bank in the U.S. in 2024 and recently announced an acquisition. These moves show that international digital banks are actively competing for U.S. customers.

To raise brand awareness in the U.S., Revolut plans to pursue sponsorship opportunities. The company already sponsors the Audi Formula 1 team, soccer clubs, and music festivals globally.

Similar partnerships in the U.S. could help boost its visibility among American consumers. Marketing investment is built into the $500 million U.S. spending plan.

Advertisement

On the topic of a potential IPO, Jajodia declined to comment on any timeline. He noted that private market capital remains available and accessible for the company.

Revolut completed a secondary share sale in November, valuing the company at $75 billion. That valuation places Revolut among the most valuable private fintech companies in the world.

Revolut’s U.K. bank continues to operate under some restrictions during a mobilization phase. The restrictions are tied to the bank’s size as it scales its operations.

However, the company appears focused on moving forward with its international growth plans. The U.S. charter application is the clearest sign yet of that ambition.

Advertisement

Source link

Advertisement
Continue Reading

Crypto World

New Berkshire Hathaway CEO still talks with Warren Buffett nearly every day

Published

on

Berkshire CEO Greg Abel on succeeding Warren Buffett: I still check in with him nearly every day
Berkshire CEO Greg Abel on succeeding Warren Buffett: I still check in with him nearly every day

Berkshire Hathaway CEO Greg Abel said he still speaks with Warren Buffett nearly every day, underscoring the continued presence of the legendary investor at the sprawling conglomerate, even after handing over the top job at the start of the year.

Buffett, who stepped down as CEO after more than six decades at the helm, remains chairman of the Omaha-based company and continues to come into the office regularly, Abel said.

“He’s in the office every day, so we’re talking every day if I’m in Omaha, we’re always connecting,” Abel said on CNBC’s “Squawk Box” Thursday. “If I’m traveling, like I was yesterday, I often check in just to catch up on what he’s seeing, what he’s hearing, what am I feeling. So if it’s not every day, it’s every couple days.”

Abel also acknowledged the challenge of stepping into Buffett’s role as Berkshire’s chief communicator to shareholders, particularly when writing his first annual letter to investors.

Advertisement

“The shoes to fill are tough on all fronts, but Warren is an exceptional communicator,” Abel said. “It was not easy. I’ve told Warren, ‘listen, the responsibilities transferred are great, but as far as the work and the task I had to do, that was the toughest.’”

Abel used the letter to shareholders to outline a clear framework of foundational values centered on financial strength and disciplined investing, vowing to preserve the blueprint Buffett carefully orchestrated since the 1960s.

Buffett offered little comfort, Abel added with a laugh. “When we were discussing it, he said, ‘the second letter doesn’t get any easier.’”

On investing, Abel said Berkshire is unlikely to move into cryptocurrencies, echoing Buffett’s longstanding skepticism of the asset class.

Advertisement

“I don’t think you’ll see crypto … I just don’t see it,” Abel said.

He left the door open to investments tied to technology, however.

“What I do see is that when it comes to technology, even from an operational perspective, where we’re seeing how we use it, the impact it’s having, it does allow us to develop strong views and a better knowledge base around certain companies that are technology companies, or how we’re using the technology. So technology will always be on the table,” Abel said.

Source link

Advertisement
Continue Reading

Crypto World

ETH, XRP, ADA, BNB, and HYPE

Published

on

eth_price_chart_0503261

This Thursday, we examine Ethereum, Ripple, Cardano, Binance Coin, and Hyperliquid in greater detail.

Ethereum (ETH)

With $2,000 support secured, Ethereum has a good shot at testing the $2,400 resistance in the near future. This also allowed the price to close the week with a 2% gain.

The current PA shows a clear reversal pattern, with a bullish engulfing candle indicating buyers are back in control. To secure their dominance, they will need to break above $2,400 as well.

Looking ahead, the most important resistance on the chart is found at $2,800. Thus, bulls may be able to keep Ethereum in a rally until then. Once there, sellers could return in force.

Advertisement
eth_price_chart_0503261
Source: TradingView

Ripple (XRP)

XRP turned bullish this week and reclaimed the $1.4 support level. While the price fell by a modest 2% compared to last week, the recent buying spree sends a strong bullish signal to market participants.

The most important resistance point is at $1.6, which will need to become support if buyers want to keep XRP in a sustained uptrend. Any weakness there will quickly be exploited by sellers.

Looking ahead, after a prolonged downtrend, this cryptocurrency is finally giving signs that the selloff may be behind us and a recovery is likely.

xrp_price_chart_0503261
Source: TradingView

Cardano (ADA)

Cardano had a difficult start this week, falling by 7%. Buyers tried multiple times to reclaim the support at 28 cents, but each time they were rejected, including this week. This is a sign of weakness.

As long as ADA keeps failing to move above 28 cents, it is unlikely for any bullish momentum to form. Should selling intensify, the price may fall to 24 cents again, as it did earlier this year.

Looking ahead, this cryptocurrency is in a tough spot. While most altcoins are giving signs of a reversal, Cardano still lags behind its peers. Hopefully, this will change soon and push the price back into an uptrend.

Advertisement
ada_price_chart_0503261
Source: TradingView

Binance Coin (BNB)

Binance Coin moved higher by 4% this week after buyers defended the $580 support well. Their current target is the resistance at $690, which may be challenging to break through, given the previous price action.

Even if sellers attempt to defend the current resistance, bullish momentum is intensifying and may be enough to drive a quick relief rally towards $900.

Looking ahead, BNB has a clear shot at a rally in the weeks to come, considering that since late 2025, the price has been in a downtrend. A sustained rally appears likely and may be quite significant.

bnb_price_chart_0503261
Source: TradingView

Hype (HYPE)

HYPE closed the week 12% higher and reclaimed a price above the key $30 support. As long as the price holds above this level, the bulls have the upper hand, and they may aim to break the resistance at $36 next.

While the momentum is bullish, there is a bit of lag since the price moved above $30. This should not last long since it would encourage sellers to return and put pressure on that support again.

Looking ahead, HYPE needs to break the $36 resistance to maintain a bullish bias in the coming weeks. Hopefully, buying volume will increase to sustain the current move into higher highs.

Advertisement
hype_price_chart_0503261
Source: TradingView
SPECIAL OFFER (Exclusive)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Disclaimer: Information found on CryptoPotato is those of writers quoted. It does not represent the opinions of CryptoPotato on whether to buy, sell, or hold any investments. You are advised to conduct your own research before making any investment decisions. Use provided information at your own risk. See Disclaimer for more information.

Source link

Advertisement
Continue Reading

Crypto World

Cardano Gets Real-World Checkout Rails in 137 Swiss Spar Stores

Published

on

Cardano Gets Real-World Checkout Rails in 137 Swiss Spar Stores

Supermarket giant Spar has enabled ADA payment rails for customers in 137 Swiss stores, as the country moves closer to its global crypto hub ambitions.

Switzerland’s push as a crypto-friendly hub is getting a new retail test case, with Cardano’s ADA token now usable for grocery purchases at Spar stores across the country.

Cardano (ADA) users can start paying for their groceries in 137 Spar supermarkets across Switzerland after the latest Open Crypto Pay integration from Swiss fintech firm DFX.swiss, the Cardano Foundation said Thursday.

Advertisement

The system is designed to process transactions in real time and allow payments directly from ADA wallets without routing through a centralized exchange. For merchants, Open Crypto pay reduces transaction costs by about two-thirds compared to traditional cards, according to the announcement.

Frederik Gregaard, the CEO of the Swiss-based Cardano Foundation, called the development the “beginning of a fundamental shift in how value moves through society,” which marks the blockchain industry’s transition from an experimental phase to “genuine financial transformation.” 

Source: Cardano Foundation

Spar first rolled out nationwide crypto and stablecoin payments in Switzerland in August 2025 for 100 stores via Binance Pay and DFX.swiss, with plans at the time to extend to 300 stores.

Related: Switzerland delays crypto tax info sharing until 2027

Tether, Lugano commit $6.4 million to global crypto hub ambitions

Separately, on Tuesday, Tether and the city of Lugano committed 5 million Swiss francs ($6.4 million) to a second phase of the city’s Plan B forum between 2026 and 2030, which aims to make Lugano a “global hub for digital asset infrastructure.”

Advertisement

Lugano has already allowed residents to pay certain municipal fees in Bitcoin (BTC) and USDt (USDT) as part of an effort to embed digital assets into the local economy.