• Latest
  • Trending
  • All
An iPhone-hacking toolkit used by Russian spies likely came from U.S military contractor

An iPhone-hacking toolkit used by Russian spies likely came from U.S military contractor

1 month ago
‘He’s The Reason I Started Following Cricket’

‘He’s The Reason I Started Following Cricket’

5 hours ago
ICSE, ISC results 2026 not tomorrow, confirms CISCE official

ICSE, ISC results 2026 not tomorrow, confirms CISCE official

5 hours ago
Sensex, Nifty Surge: Crude Oil Drop & Iran-US Peace Talks Boost Indian Markets

Sensex, Nifty Surge: Crude Oil Drop & Iran-US Peace Talks Boost Indian Markets

6 hours ago
Did Mini Mathur take a swipe at Alia Bhatt’s hosting skills? Call Me Bae actor clarifies

Did Mini Mathur take a swipe at Alia Bhatt’s hosting skills? Call Me Bae actor clarifies

6 hours ago
Yelp’s updated AI assistant can answer questions and book a restaurant or service in one conversation

Yelp’s updated AI assistant can answer questions and book a restaurant or service in one conversation

7 hours ago
The Limitations of GLP-1 Therapies and the Need for Early Detection, ETHealthworld

The Limitations of GLP-1 Therapies and the Need for Early Detection, ETHealthworld

7 hours ago
JD(U) names Shrawon Kumar as legislative party leader in Bihar

JD(U) names Shrawon Kumar as legislative party leader in Bihar

7 hours ago
DSP dies of accidental gunshot while cleaning service weapon in Phagwara

DSP dies of accidental gunshot while cleaning service weapon in Phagwara

8 hours ago
JEE Main 2026 Result: Cut-off not met? These are the alternatives | Education News

JEE Main 2026 Result: Cut-off not met? These are the alternatives | Education News

10 hours ago
India’s Outward FDI Rises to .06 Billion in March

India’s Outward FDI Rises to $7.06 Billion in March

10 hours ago
Vance heads to Pak as ceasefire deadline nears; Iran yet to confirm

Vance heads to Pak as ceasefire deadline nears; Iran yet to confirm

12 hours ago
‘If you attempt to run…’: US helicopter gunner warns ship near Iran port as 27 vessels returned — watch

‘If you attempt to run…’: US helicopter gunner warns ship near Iran port as 27 vessels returned — watch

15 hours ago
Tuesday, April 21, 2026
  • PRESS RELEASE
  • ADVERTISE
  • CONTACT
  • Game
India News Online
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
    • All
    • Hindi Songs
    • Punjabi Songs
    इंस्टाग्राम वाली बीबी😃90’S Old Hindi Songs🤣90s Love Song😍Udit Narayan,Alka Yagnik,Kumar Sanu song

    इंस्टाग्राम वाली बीबी😃90’S Old Hindi Songs🤣90s Love Song😍Udit Narayan,Alka Yagnik,Kumar Sanu song

    इंसानियत 😃90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar Sanu songs

    इंसानियत 😃90’S Old Hindi Songs 🥺90s Love Song 😍Udit Narayan, Alka Yagnik, Kumar Sanu songs

    Kheti | Hardev Mahinangal | Amnindr Bhangu | Latest Punjabi Songs 2026 | Lipci | Mukaam records

    Kheti | Hardev Mahinangal | Amnindr Bhangu | Latest Punjabi Songs 2026 | Lipci | Mukaam records

    PANGA (Official Video) | Labh Heera | Jaskaran Grewal | New Punjabi Songs 2026 |Latest Punjabi Songs

    PANGA (Official Video) | Labh Heera | Jaskaran Grewal | New Punjabi Songs 2026 |Latest Punjabi Songs

    Asla – Watan Sahi [Official MV] Latest Punjabi Song – K Million Music

    Asla – Watan Sahi [Official MV] Latest Punjabi Song – K Million Music

    Game – Surjit Bhullar | Mista Baaz | Bittu Cheema | Latest Punjabi Song 2026

    Game – Surjit Bhullar | Mista Baaz | Bittu Cheema | Latest Punjabi Song 2026

    Latest Punjabi Hit Songs 💞 Top Punjabi Songs Collection ✨ #punjabisongs #punjabimusic

    Latest Punjabi Hit Songs 💞 Top Punjabi Songs Collection ✨ #punjabisongs #punjabimusic

    Udaariyaan 💗🫠 ~ Satinder Sartaj | Punjabi song | #song #shorts #lyrics

    Udaariyaan 💗🫠 ~ Satinder Sartaj | Punjabi song | #song #shorts #lyrics

    Diljit Dosanjh : Dealer (Official Music Video) Virk Andaaz : Da Future

    Diljit Dosanjh : Dealer (Official Music Video) Virk Andaaz : Da Future

  • Travel
  • Game
No Result
View All Result
India News
No Result
View All Result
Home Technology

An iPhone-hacking toolkit used by Russian spies likely came from U.S military contractor

by India News Online Team
March 10, 2026
in Technology
0
An iPhone-hacking toolkit used by Russian spies likely came from U.S military contractor
Share on FacebookShare on TwitterShare on Email


A mass hacking campaign targeting iPhone users in Ukraine and China used tools that were likely designed by U.S. military contractor L3Harris, TechCrunch has learned. The tools, which were intended for Western spies, wound up in the hands of various hacking groups, including Russian government spooks and Chinese cybercriminals.

Last week, Google revealed that over the course of 2025 it discovered that a sophisticated iPhone-hacking toolkit had been used in a series of global attacks. The toolkit, dubbed “Coruna” by its original developer, was made of 23 different components first used “in highly targeted operations” by an unnamed government customer of an unspecified “surveillance vendor.” It was then used by Russian government spies against a limited number of Ukrainians and finally by Chinese cybercriminals “in broad-scale” campaigns with the goal of stealing money and cryptocurrency. 

Researchers at mobile cybersecurity company iVerify, which independently analyzed Coruna, said they believed it may have been originally built by a company that sold it to the U.S. government.

Two former employees of government contractor L3Harris told TechCrunch that Coruna was, at least in part, developed by the company’s hacking and surveillance tech division, Trenchant. The two former employees both had knowledge of the company’s iPhone hacking tools. Both spoke on condition of anonymity because they weren’t authorized to talk about their work for the company.

“Coruna was definitely an internal name of a component,” said one former L3Harris employee, who was familiar with iPhone hacking tools as part of their work at Trenchant. 

“Looking at the technical details,” this person said, referring to some of the evidence Google published, “so many are familiar.” 

Contact Us

Do you have more information about Coruna, or other government hacking and spyware tools? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or by email.

The former employee said the overarching Trenchant toolkit housed several different components, including Coruna and related exploits. Another former employee confirmed that some of the details included in the published hacking toolkit came from Trenchant. 

L3Harris sells Trenchant’s hacking and surveillance tools exclusively to the U.S. government and its allies in the so-called Five Eyes intelligence alliance, which includes Australia, Canada, New Zealand, and the United Kingdom. Given Trenchant’s limited number of customers, it’s possible that Coruna was originally acquired and used by one of these governments’ intelligence agencies before falling into unintended hands, though it’s unclear how much of the published Coruna hacking toolkit were developed by L3Harris Trenchant.

An L3Harris spokesperson did not respond to a request for comment.

How Coruna went from the hands of a Five Eyes government contractor to a Russian government hacking group, and then to a Chinese cybercrime gang is unclear. 

But some of the circumstances appear similar to the case of Peter Williams, a former general manager at Trenchant. From 2022 until he resigned in mid-2025, Williams sold eight company hacking tools to Operation Zero, a Russian company that offers millions of dollars in exchange for zero-day exploits, meaning vulnerabilities that are unknown to the affected vendor. 

Williams, a 39-year-old Australian citizen, was sentenced to seven years in prison last month, after he admitted to stealing and selling the eight Trenchant hacking tools to Operation Zero for $1.3 million.  

The U.S. government said Williams, who took advantage of having “full access” to Trenchant’s networks, “betrayed” the United States and its allies. Prosecutors accused him of leaking tools that could have allowed whoever used them to “potentially access millions of computers and devices around the world,” suggesting the tools relied on vulnerabilities affecting widely used software like iOS.  

Operation Zero, which was sanctioned by the U.S. government last month, claims to work exclusively with the Russian government and local companies. The U.S Treasury claimed that the Russian broker sold Williams’ “stolen tools to at least one unauthorized user.”

That would explain how the Russian espionage group, which Google has only identified as UNC6353, acquired Coruna and deployed it on compromised Ukrainian websites so that it would hack certain iPhone users from a specific geolocation who unwittingly visited the malicious site.

It is possible that once Operation Zero acquired Coruna and potentially sold it to the Russian government, the broker then resold the toolkit to someone else, perhaps another broker, another country, or even directly to cybercriminals. The Treasury alleged that a member of the Trickbot ransomware gang worked with Operation Zero, tying the broker to financially motivated hackers.

At that point, Coruna may have passed to other hands until it reached Chinese hackers. According to U.S. prosecutors, Williams recognized code that he wrote and sold to Operation Zero later being used by a South Korean broker.

the logo Kaspersky made for Operation Triangulation next to the L3Harris logo. Image: Kaspersky and L3Harris

Operation Triangulation

Google researchers wrote on Tuesday that two specific Coruna exploits and underlying vulnerabilities, called Photon and Gallium by their original developers, were used as zero-days in Operation Triangulation, a sophisticated hacking campaign allegedly used against Russian iPhone users. Operation Triangulation was first revealed by Kaspersky in 2023. 

Rocky Cole, the co-founder of iVerify, told TechCrunch that “the best explanation based on what’s known right now” points to Trenchant and the U.S. government being the original developers and customers of Coruna. Although, Cole added, he isn’t claiming this “definitively.”

That assessment, he said, is based on three factors. The timeline of Coruna’s use lines up with the Williams’ leaks, the structure of three modules — Plasma, Photon, and Gallium — found in Coruna bear strong similarities with Triangulation, and Coruna re-used some of the same exploits used in that operation, he said.

According to Cole, “people close to the defense community” claim Plasma was used in Operation Triangulation, “although there’s no public evidence of that.” (Cole previously worked at the U.S. National Security Agency.)

According to Google and iVerify, Coruna was designed to hack iPhone models running iOS 13 through 17.2.1, released between September 2019 and December 2023. Those dates line up with the timeline of some of Williams’s leaks, and the discovery of Operation Triangulation. 

One of the former Trenchant employees told TechCrunch that when Triangulation was first revealed in 2023, other employees at the company believed that at least one of the zero-days caught by Kaspersky “were from us, and potentially ‘ripped out’ of the” overarching project that included Coruna.

Another breadcrumb that points to Trenchant — as security researcher Costin Raiu noted — is the use of bird names for some of the 23 tools, such as Cassowary, Terrorbird, Bluebird, Jacurutu, and Sparrow. In 2021, The Washington Post revealed that Azimuth, one of the two startups later acquired by L3Harris and merged into Trenchant, had sold a hacking tool called Condor to the FBI in the infamous San Bernardino iPhone cracking case. 

After Kaspersky published its research on Operation Triangulation, Russia’s Federal Security Service (FSB) accused the NSA of hacking “thousands” of iPhones in Russia, targeting diplomats in particular. A Kaspersky spokesperson said at the time that the company did not have information on the FSB’s claims. The spokesperson did note that “indicators of compromise” — meaning evidence of a hack — identified by the Russian National Coordination Centre for Computer Incidents (NCCCI) were the same ones that Kaspersky had identified.

Boris Larin, a security researcher at Kaspersky, told TechCrunch in an email that “despite our extensive research, we are unable to attribute Operation Triangulation to any known [Advanced Persistent Threat] group or exploit development company.” 

Larin explained that Google linked Coruna to Operation Triangulation because they both exploit the same two vulnerabilities — Photon and Gallium. 

“Attribution cannot be based solely on the fact of exploitation of these vulnerabilities. All the details of both vulnerabilities have long been publicly available,” and thus anyone could have taken advantage of them, he said, adding that those two shared vulnerabilities “are just the tip of the iceberg.”  

Kaspersky never publicly accused the U.S. government of being behind Operation Triangulation. Curiously, the logo that the company created for the campaign — an apple logo composed of several triangles — is reminiscent of the L3Harris logo. It may not be a coincidence. Kaspersky has previously said it wouldn’t attribute a hacking campaign publicly while quietly signaling that it actually knew who was behind it, or who provided the tools for it.

In 2014, Kaspersky announced that it had caught a sophisticated and elusive government hacking group known as “Careto” (Spanish for “The Mask”). The company only said the hackers spoke Spanish. But the illustration of a mask that the company used in its report included the red and yellow colors of Spain’s flag, bull’s horns and nose ring, and castanets.

As TechCrunch revealed last year, Kaspersky researchers had privately concluded that “there was no doubt,” as one of them put it, that Careto was run by the Spanish government. 

On Wednesday, cybersecurity journalist Patrick Gray said on an episode of his podcast Risky Business that he thought — based on “bits and pieces” he was confident about — that what Williams leaked to Operation Zero was the hacking kit used in the Triangulation campaign.   

Apple, Google, Kaspersky, and Operation Zero did not respond to requests for comment.



Source link

Tags: ContractoriPhonehackingMilitaryRussianSpiestoolkitU.S
Share196Tweet123Send

Related Posts

Yelp’s updated AI assistant can answer questions and book a restaurant or service in one conversation
Technology

Yelp’s updated AI assistant can answer questions and book a restaurant or service in one conversation

April 21, 2026
John Ternus will replace Tim Cook as Apple CEO
Technology

John Ternus will replace Tim Cook as Apple CEO

April 20, 2026
A Blue Origin rocket failed to correctly place a BlueBird satellite from satellite networking company AST into its intended orbit; ASTS falls 14% pre-market (Jake Rudnitsky/Bloomberg)
Technology

A Blue Origin rocket failed to correctly place a BlueBird satellite from satellite networking company AST into its intended orbit; ASTS falls 14% pre-market (Jake Rudnitsky/Bloomberg)

April 20, 2026
Infosys Q4 results preview: Set for soft quarter; FY27 growth outlook seen at 2–5%
Technology

Infosys Q4 results preview: Set for soft quarter; FY27 growth outlook seen at 2–5%

April 19, 2026
Load More
  • Trending
  • Comments
  • Latest
9 Festivals to Celebratein August in India

9 Festivals to Celebratein August in India

August 8, 2025
Corruption cases against govt officials: SC bats for striking balance | Latest News India

Corruption cases against govt officials: SC bats for striking balance | Latest News India

August 5, 2025
Guru Randhawa – SIRRA ( Official Video )

Guru Randhawa – SIRRA ( Official Video )

July 1, 2025
‘He’s The Reason I Started Following Cricket’

‘He’s The Reason I Started Following Cricket’

0
Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

Baharon Phool Barsao – Suraj – Rajendra Kumar, Vyjayanthimala – Old Hindi Songs

0
Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

Dil Ka Rishta Song – Aishwarya Rai,Arjun Rampal, Alka Yagnik,Udit Narayan,Kumar Sanu, Nadeem-Shravan

0
‘He’s The Reason I Started Following Cricket’

‘He’s The Reason I Started Following Cricket’

April 21, 2026
ICSE, ISC results 2026 not tomorrow, confirms CISCE official

ICSE, ISC results 2026 not tomorrow, confirms CISCE official

April 21, 2026
Sensex, Nifty Surge: Crude Oil Drop & Iran-US Peace Talks Boost Indian Markets

Sensex, Nifty Surge: Crude Oil Drop & Iran-US Peace Talks Boost Indian Markets

April 21, 2026
India News Online

24x7 Online News From India
India News Online is your news, entertainment, music fashion website. We provide you with the latest breaking news and videos straight from the entertainment industry.

Categories

  • Business
  • Entertainment
  • Health
  • Hindi News
  • Hindi Songs
  • India
  • International
  • Lifestyle
  • Panjab
  • Politics
  • Punjabi Songs
  • Sports
  • Technology
  • Travel
  • Uncategorized
No Result
View All Result

Recent Posts

  • ‘He’s The Reason I Started Following Cricket’
  • ICSE, ISC results 2026 not tomorrow, confirms CISCE official
  • Sensex, Nifty Surge: Crude Oil Drop & Iran-US Peace Talks Boost Indian Markets
  • Home
  • Disclaimer
  • DMCA
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact

Copyright © 2021 - India News Online.

No Result
View All Result
  • Home
  • News
    • India
    • Punjab
    • International
    • Entertainment
  • Hindi News
  • Politics
  • Health
  • Business
  • Sports
  • Technology
  • Lifestyle
  • Video
  • Travel
  • Game

Copyright © 2021 - India News Online.