
A significant hacking initiative that has impacted iPhone users in Ukraine and China appears to have utilized tools likely developed by L3Harris, a U.S. military contractor. These sophisticated hacking resources, originally intended for Western intelligence operations, have reportedly fallen into the hands of various hacking factions, including Russian state-sponsored operatives and Chinese cybercriminal groups. Last week, Google disclosed that throughout 2025, it identified an advanced toolkit known as “Coruna,” which had been employed in numerous global cyberattacks. This toolkit comprises 23 distinct components and was initially crafted for a government client by an undisclosed surveillance vendor. Following its creation, the tools were subsequently repurposed for operations by Russian intelligence against select Ukrainian targets and later utilized in extensive campaigns by Chinese hackers aimed at financial theft and cryptocurrency fraud. Mobile security experts at iVerify conducted an independent analysis of Coruna and suggested that the toolkit was likely developed by a company that supplied it to the U.S. government. Two former employees of L3Harris, who spoke under anonymity due to their non-disclosure agreements, confirmed to TechCrunch that Coruna was partially developed by the company's Trenchant division, which specializes in hacking and surveillance technologies. One employee noted, “Coruna was definitely an internal name for a component,” adding that the technical details published by Google seemed familiar. The journey of Coruna from a government contractor to a Russian espionage group and ultimately to Chinese cybercriminals raises concerns about cybersecurity and the potential misuse of such tools. While the exact path remains unclear, similarities have been drawn to the case of Peter Williams, a former Trenchant executive, who was sentenced to seven years in prison for selling eight hacking tools to a Russian firm known as Operation Zero. This firm is notorious for trading zero-day exploits, which are vulnerabilities unknown to the software producers. Williams, who had full access to Trenchant’s networks, admitted to betraying the U.S. and its allies by leaking tools capable of compromising millions of devices globally. The U.S. Treasury has implicated Operation Zero in transactions with Russian government entities, suggesting a complex web of sales that may have enabled the transfer of Coruna to unauthorized users. As the lines between government-sanctioned hacking and criminal activities blur, the implications of these revelations are profound. The toolkit designed for intelligence operations has ended up in the hands of entities with potentially malicious intent, showcasing the vulnerabilities in the current cybersecurity landscape. Tech experts believe that the connection between the U.S. military contractor and the ensuing global hacking campaigns could have far-reaching consequences, not just for national security but also for international relations. The situation demands further investigation into how such powerful tools can be safeguarded against misuse in the future.
In the realm of cybersecurity, few figures are as intriguing as Phineas Fisher, a hacker who has evaded capture for near...
TechCrunch | Jul 25, 2026, 21:00
Nvidia has successfully forged a significant partnership with South Korea's SK Hynix to secure memory supplies essential...
CNBC | Jul 25, 2026, 05:15
Monday.com, the innovative work management platform based in Tel Aviv, has recently announced significant layoffs, attri...
TechCrunch | Jul 26, 2026, 01:45
Science Corp is poised to introduce a revolutionary retina chip in Europe, designed to restore partial vision for indivi...
Business Today | Jul 25, 2026, 01:00
As technology continues to evolve, a notable shift is occurring in the relationship between humans and artificial intell...
Business Insider | Jul 25, 2026, 09:50