
A recent investigation has revealed that a widespread hacking initiative targeting iPhone users in Ukraine and China was likely facilitated by tools created by the U.S. military contractor L3Harris. Originally intended for Western intelligence operations, these tools ended up in the possession of various hacking collectives, including Russian and Chinese cyber operatives. According to Google, a sophisticated hacking toolkit identified as "Coruna" has been linked to numerous international cyber attacks in 2025. This toolkit consists of 23 components and was initially employed for targeted operations by an undisclosed government client. The tools were later utilized by Russian spies against select Ukrainians and subsequently by Chinese cybercriminals in large-scale campaigns aimed at financial theft, including cryptocurrency. Experts from mobile cybersecurity firm iVerify conducted an analysis of Coruna and suggested that it may have originated from a company that sold its services to the U.S. government. Two former employees from L3Harris disclosed that Coruna was partially developed by the firm’s Trenchant division, which specializes in hacking and surveillance technologies. Both individuals spoke under the condition of anonymity, citing confidentiality agreements. "Coruna was definitely an internal name of a component," noted one former employee, who was familiar with the hacking tools. This person pointed out that the technical details shared by Google resonate with their experiences at Trenchant. The toolkit's journey from a Five Eyes government contractor to Russian and Chinese hackers remains murky. However, parallels can be drawn with a case involving Peter Williams, a former Trenchant manager who sold several hacking tools to Operation Zero, a Russian entity known for dealing in zero-day exploits. Williams was sentenced to seven years in prison after confessing to selling these tools for $1.3 million, which the U.S. government deemed a betrayal. The U.S. Treasury has implicated Operation Zero in selling the stolen tools to unauthorized users, potentially including the Russian espionage group identified as UNC6353. This group reportedly deployed Coruna to breach Ukrainian websites, targeting iPhone users in specific locations. The flow of Coruna may have shifted through various intermediaries before reaching Chinese hackers. Adding to the intrigue, Google researchers indicated that specific exploits from Coruna were utilized in a sophisticated hacking campaign known as Operation Triangulation, aimed at Russian iPhone users. This connection raises questions about the original developers of Coruna, with some experts suggesting that Trenchant and the U.S. government are likely the source. Despite the circumstantial evidence linking L3Harris to Coruna, the company did not respond to requests for comments regarding these allegations. As the investigation unfolds, the implications of these findings could have significant repercussions for both national security and international cyber relations.
At the Pennsylvania Defense and Innovation Summit, JPMorgan Chase CEO Jamie Dimon raised significant concerns regarding ...
Business Insider | Jul 16, 2026, 05:00Shares of Chinese tech leaders Alibaba and Baidu experienced significant gains on Thursday, buoyed by their recent partn...
CNBC | Jul 16, 2026, 03:25
In a recent broadcast, CNBC’s Jim Cramer called for concrete evidence that artificial intelligence is delivering financi...
CNBC | Jul 15, 2026, 23:05
Lululemon, the well-known activewear brand, has made a significant investment in Syntetica, a French startup that has de...
TechCrunch | Jul 16, 2026, 04:30
Google has just given fans a sneak peek at its highly anticipated Pixel 11 series, set to launch on August 12, 2026. The...
Business Today | Jul 16, 2026, 06:10