Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Password manager Dashlane says hackers stole some customers’ password vaults

Board, the new gaming startup from Mirror founder Brynn Putnam, raises $20 million, has already sold thousands

How Europe’s AI strategy diverges from Silicon Valley’s

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Anthropic scales Claude Mythos to critical infrastructure in 15+ countries

    2 June 2026

    Florida sues OpenAI’s Sam Altman in first-of-its-kind violent crime lawsuit

    2 June 2026

    The internet is being remade for machines

    1 June 2026

    Understanding the AI ​​psychosis debate

    31 May 2026

    ‘What a joke’: Github Copilot’s new token-based pricing upsets developers

    31 May 2026
  • Apps

    Meta is testing ‘Series’ for episodic Reels on Instagram and Facebook

    2 June 2026

    A new app, The Mall, creates a universal flow for online shopping

    2 June 2026

    DuckDuckGo makes its ‘AI-free’ search engine easier to access as traffic grows

    1 June 2026

    TikTok’s road to becoming a super app

    31 May 2026

    YouTube adds new podcast features, including an AI recommendation tool and ‘Auto Speed’

    30 May 2026
  • Crypto

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026
  • Fintech

    Last 24 hours to save up to $410 on your Disrupt 2026 ticket

    29 May 2026

    2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

    28 May 2026

    Robinhood now allows your AI agents to trade stocks

    28 May 2026

    Disrupt 2026 Early Bird ticket savings expire in 3 days

    27 May 2026

    Disrupt 2026 Early Bird ticket prices end May 29

    26 May 2026
  • Hardware

    Nvidia chases $200 billion CPU market with AI agent computing from Microsoft, Dell and HP

    2 June 2026

    This $300 Pizza Oven Can Easily Help Revive Your Summer Pizza Nights

    30 May 2026

    Kiwibit’s artificial intelligence bird feeder is my new backyard friend

    29 May 2026

    Vertu wants CEOs to run companies from a foldable AI starting at $6,880

    29 May 2026

    Oura unveils its Ring 5 with a thinner, lighter design starting at $399

    28 May 2026
  • Media & Entertainment

    The two biggest movies of this weekend were both directed by YouTubers

    31 May 2026

    The two biggest movies of this weekend were both directed by YouTubers

    30 May 2026

    YouTube will automatically flag videos with artificial intelligence

    28 May 2026

    Meta launches Instagram, Facebook and WhatsApp subscriptions, with more to follow, including AI plans

    27 May 2026

    Spotify now lets you view narrated magazine articles as well

    26 May 2026
  • Security

    Password manager Dashlane says hackers stole some customers’ password vaults

    2 June 2026

    Hackers took over Instagram accounts by tricking the Meta AI support chatbot into granting access

    1 June 2026

    Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

    30 May 2026

    Microsoft is under fire for threatening a security researcher with a criminal investigation

    29 May 2026

    A security flaw in prison payphone service Pay Tel exposed publicly the driver’s licenses of more than 300,000 callers

    29 May 2026
  • Startups

    Board, the new gaming startup from Mirror founder Brynn Putnam, raises $20 million, has already sold thousands

    2 June 2026

    From Stage to Future: Where Are Startup Battlefield Alumni Now?

    2 June 2026

    Revolut offers service to thousands of users in India ahead of wider rollout

    1 June 2026

    The deadline to submit applications for the Startup Battlefield 200 has been extended to June 8

    30 May 2026

    H1 secures $40M from CVS, proving SaaS startups can still attract investment

    30 May 2026
  • Transportation

    Defense tech darling Mach Industries hits $1.8 billion valuation, 4x jump in one year

    2 June 2026

    SpaceX says it may issue ‘significant’ equity in ‘future transactions’

    1 June 2026

    TechCrunch Mobility: It doesn’t matter that people hate the Ferrari Luce

    31 May 2026

    Rivian is under investigation for rear suspension failures on R1 models

    30 May 2026

    Waymo’s newest robotaxi is Chinese-made, built to make money, and is now accepting riders

    30 May 2026
  • Venture

    How Europe’s AI strategy diverges from Silicon Valley’s

    2 June 2026

    How to make the Startup Battlefield Top 20 — and what each company gets regardless

    2 June 2026

    Black founders raise highest quarterly funding since 2022, but there’s a catch

    31 May 2026

    Snap alums reveal Ghost Angels fund

    31 May 2026

    The groupthink explosion: what three top VCs really think about the AI ​​frenzy

    30 May 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»US military contractor likely built iPhone hacking tools used by Russian spies in Ukraine
Security

US military contractor likely built iPhone hacking tools used by Russian spies in Ukraine

techtost.comBy techtost.com10 March 202608 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Us Military Contractor Likely Built Iphone Hacking Tools Used By
Share
Facebook Twitter LinkedIn Pinterest Email

A mass hacking campaign targeting iPhone users in Ukraine and China used tools likely designed by US military contractor L3Harris, according to TechCrunch. The tools, which were intended for Western spies, ended up in the hands of various hacking groups, including Russian government terrorists and Chinese cybercriminals.

Last week, Google revealed that during 2025, it discovered that a sophisticated iPhone hacking toolkit had been used in a series of global attacks. The toolkit, named “Coruna” by its original developer, was constructed from 23 different components that were first used “in highly targeted operations” by an unnamed government customer of an unspecified “surveillance vendor.” It was then used by Russian government spies against a limited number of Ukrainians, and finally by Chinese cybercriminals in “wide-scale” campaigns to steal money and cryptocurrencies.

Researchers at mobile phone company iVerify, which independently analyzed Coruñasaid they believed it may have been originally manufactured by a company that sold it to the US government.

Two former employees of government contractor L3Harris told TechCrunch that Coruna was developed, at least in part, by the company’s hacking and surveillance technology division, Trenchant. The two former employees both had knowledge of the company’s iPhone hacking tools. Both spoke on condition of anonymity because they were not authorized to talk about their work for the company.

“Coruna was definitely an inside name of a component,” said a former L3Harris employee who was familiar with iPhone hacking tools as part of his work at Trenchant.

“Looking at the technical details,” this person said, referring to some of the data released by Google, “so much is known.”

Contact us

Do you have more information about Coruna or other government hacking and spyware tools? From a non-working device, Lorenzo Franceschi-Bicchierai can be reached securely on Signal at +1 917 257 1382 or via Telegram, Keybase and Wire @lorenzofb or via email.

The former employee said the general Trenchant toolbox was home to many different elements, including Coruna and related holdings. Another former employee confirmed that some of the details included in the published hacking toolkit came from Trenchant.

L3Harris sells Trenchant’s hacking and surveillance tools exclusively to the US government and its allies in the so-called Five Eyes intelligence alliance, which includes Australia, Canada, New Zealand and the United Kingdom. Given Trenchant’s limited number of clients, it is possible that Coruna was originally acquired and used by one of those governments’ intelligence agencies before falling into unwitting hands, although it is unclear how much of the published Coruna hacking toolkit was developed by L3Harris Trenchant.

A representative for L3Harris did not respond to a request for comment.

How Coruna went from the hands of a Five Eyes government contractor to a Russian government hacking group and then to a Chinese cybercrime gang is unclear.

But some of the circumstances seem similar to the case of Peter Williams, Trenchant’s former managing director. From 2022 until his resignation in mid-2025, Williams sold eight corporate hacking tools to Operation Zero, a Russian company that offers millions of dollars in exchange for zero-day exploits, that is, vulnerabilities unknown to the affected vendor.

Williams, a 39-year-old Australian citizen, was sentenced to seven years in prison last month after he admitted stealing and selling Trenchant’s eight hacking tools to Operation Zero for $1.3 million.

The US government said Williams, who took advantage of “full access” to Trenchant’s networks, “betrayed” the United States and its allies. Prosecutors accused him of leaking tools that could allow anyone using them to “potentially access millions of computers and devices around the world,” suggesting the tools are based on vulnerabilities affecting widely used software such as iOS.

Operation Zero, which was sanctioned by the US government last month, claims to be working exclusively with the Russian government and local companies. The US Treasury Department alleged that the Russian broker sold Williams’ “stolen tools” to at least one unauthorized user.

This would explain how the Russian espionage group, which Google has identified only as UNC6353, obtained Coruna and deployed it on hacked Ukrainian websites to hack certain iPhone users from a specific geographic location who were unwittingly visiting the malicious website.

It is possible that once Operation Zero acquired Coruna and possibly sold it to the Russian government, the broker then resold the toolkit to someone else, perhaps another broker, in another country, or even directly to cybercriminals. The Treasury Department alleged that a member of the Trickbot ransomware gang worked with Operation Zero, linking the broker to financially motivated hackers.

At that point, Coruna might have changed hands until it reached Chinese hackers. According to US prosecutors, Williams identified the code he wrote and sold to Operation Zero and was later used by a South Korean broker.

the logo made by Kaspersky for Operation Triangulation next to the L3Harris logo.Image Credits:Kaspersky and L3Harris

Triangulation function

Google researchers wrote on Tuesday that two specific Coruna exploits and underlying vulnerabilities, named Photon and Gallium by their original developers, were used as zero-days in Operation Triangulation, a sophisticated hacking campaign allegedly used against Russian iPhone users. Operation Triangulation was first disclosed by Kaspersky in 2023.

Rocky Cole, the co-founder of iVerify, told TechCrunch that “the best explanation based on what is known right now” points to Trenchant and the US government being the original developers and customers of Coruna. Although, Cole added, he doesn’t claim that “definitively.”

That assessment, he said, is based on three factors. The timing of Coruña’s use coincides with Williams’ leaks. The structure of three units — Plasma, Photon and Gallium — found in Coruña bear strong similarities to Trigonism. and Coruna reused some of the same assets used in that business.

According to Cole, “people close to the defense community” claim that Plasma was used in Operation Triangulation, “although there is no public evidence of this.” (Cole previously worked for the US National Security Agency.)

According to Google and iVerify, Coruna was designed to hack iPhone models running iOS 13 to 17.2.1, released between September 2019 and December 2023. These dates align with the timeline of some of Williams’ leaks and the Operation Triangulation discovery.

One of Trenchant’s former employees told TechCrunch that when Triangulation was first revealed in 2023, other employees at the company believed that at least one of the zero-days that Kaspersky caught “was from us and possibly ‘detached’ from the overall project involving Coruna.”

Another toast showing Trenchant — as noted by security researcher Costin Raiu — is the use of bird names for some of the 23 tools, including Cassowary, Terrorbird, Bluebird, Jacurutu and Sparrow. In 2021, the Washington Post revealed that azimuth, one of the two startups later acquired by L3Harris and merged into Trenchanthad sold a hacking tool called Condor to the FBI in San Bernardino’s famous iPhone breaking case.

After Kaspersky published its investigation into Operation Triangulation, Russia’s Federal Security Service (FSB) accused the NSA of hacking “thousands” of iPhones in Russia, particularly targeting diplomats. A Kaspersky spokesman said at the time that the company had no information about the FSB’s allegations. The spokesman noted that the “indicators of compromise” – meaning evidence of an intrusion – detected by the Russian National Coordination Center for Computer Incidents (NCCCI) were the same as those detected by Kaspersky.

Boris Larin, a security researcher at Kaspersky, told TechCrunch in an email that “despite our extensive investigation, we are unable to attribute Operation Triangulation to any known [Advanced Persistent Threat] group development or holding company’.

Larin explained that Google linked Coruna to Operation Triangulation because they both exploit the same two vulnerabilities – Photon and Gallium.

“The performance cannot be based solely on the fact that these vulnerabilities were exploited. All the details of both vulnerabilities have long been publicly available,” he said, adding that these two shared vulnerabilities “are just the tip of the iceberg.”

Kaspersky has never publicly accused the US government of being behind Operation Triangulation. Interestingly, the logo created by the company for the campaign is an apple logo consisting of many triangles — reminds the L3Harris logo. It may not be a coincidence. Kaspersky had previously said it would not publicly attribute a hacking campaign, tacitly signaling that it actually knew who was behind it or who provided the tools for it.

In 2014, Kaspersky was announced that he had captured a sophisticated and elusive government hacking group known as “Careto” (Spanish for “the Mask”). The company said only that the hackers spoke Spanish. But the depiction of a mask the company used in its exhibition included the red and yellow colors of the Spanish flag, the bull’s horns and nose ring, and castanets.

As TechCrunch revealed last year, Kaspersky researchers had privately concluded that there was “no doubt,” as one of them put it, that Careto was run by the Spanish government.

On Wednesday, cybersecurity reporter Patrick Gray he said on an episode of the Risky Business podcast that he thought – based on the “bits and pieces” he was sure of – that what Williams leaked to Operation Zero was the hacking kit used in the Triangulation campaign.

Apple, Google and Operation Zero did not respond to requests for comment.

This post was originally posted at 6:56 pm. PT

Acute apple built China contractor cyber security cybercrime espionage Exclusive hacker Hacking iPhone Kaspersky L3harris military Peter Williams Russia Russian spies tools Triangulation function Ukraine
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAI networking startup Eridu emerges from stealth with hefty $200M Series A
Next Article YouTube extends fake AI detection to politicians, government officials and journalists
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Password manager Dashlane says hackers stole some customers’ password vaults

2 June 2026

Hackers took over Instagram accounts by tricking the Meta AI support chatbot into granting access

1 June 2026

Revolut offers service to thousands of users in India ahead of wider rollout

1 June 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Password manager Dashlane says hackers stole some customers’ password vaults

2 June 2026

Board, the new gaming startup from Mirror founder Brynn Putnam, raises $20 million, has already sold thousands

2 June 2026

How Europe’s AI strategy diverges from Silicon Valley’s

2 June 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Last 24 hours to save up to $410 on your Disrupt 2026 ticket

29 May 2026

2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

28 May 2026

Robinhood now allows your AI agents to trade stocks

28 May 2026
Startups

Board, the new gaming startup from Mirror founder Brynn Putnam, raises $20 million, has already sold thousands

From Stage to Future: Where Are Startup Battlefield Alumni Now?

Revolut offers service to thousands of users in India ahead of wider rollout

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.