US Government iPhone-Hacking Toolkit Leaked to Russian Spies and Cybercriminals
By
alwillis
Baker's choice. Dense with flavour, light on filler.
Summary
A sophisticated iPhone-hacking toolkit, originally suspected to be developed by a US government contractor, has been transferred from Russian spies targeting Ukrainians to cybercriminals stealing cryptocurrency from Chinese-speaking victims. The hacking technique can hijack iPhones simply by visiting a website and has likely infected tens of thousands of devices. This represents a rare and concerning development where state-level surveillance tools have leaked into the criminal underworld.
Key quotes
· 4 pulledAn iPhone-hacking technique used in the wild to indiscriminately hijack the devices of any iOS user who merely visits a website represents a rare and shocking event in the cybersecurity world.
It appears to have traveled from the hands of Russian spies who used it to target Ukrainians to a cybercriminal operation designed to steal cryptocurrency from Chinese-speaking victims—and some clues suggest it may have been originally created by a US contractor.
A highly sophisticated set of iPhone hijacking techniques has likely infected tens of thousands of phones or more.
Now one powerful hacking toolkit at the center of multiple mass iPhone exploitation campaigns has taken an even rarer and more disturbing path.
You might also wanna read
Phishing Campaign Targets Signal Users by Stealing Backup Recovery Keys
A new wave of phishing attacks is targeting Signal users by impersonating the app's support team. Hackers send messages inside Signal claimi
cybersecuritynews.com·4h agoNew phishing campaign targets Signal users to steal chat backup recovery keys
Hackers are targeting Signal users in a new phishing campaign that attempts to steal their chat backups. The attackers pose as Signal's supp
Weekly cybersecurity roundup: FortiClient EMS infostealer, Trend Micro Apex One exploit, and crypto payment security
A weekly roundup of cybersecurity news, featuring an interview with Coinflow's CISO about crypto payment security under AI-driven threats, c

CISA Adds Palo Alto Networks PAN-OS Authentication Bypass Vulnerability to Known Exploited Vulnerabilities Catalog
CISA has added a new vulnerability (CVE-2026-0257) to its Known Exploited Vulnerabilities (KEV) Catalog, affecting Palo Alto Networks PAN-OS

CISA Adds Palo Alto Networks PAN-OS Authentication Bypass Vulnerability to Known Exploited Vulnerabilities Catalog
CISA has added a new vulnerability (CVE-2026-0257) to its Known Exploited Vulnerabilities (KEV) Catalog, affecting Palo Alto Networks PAN-OS
Microsoft warns of crypto mining malware disguised as fake downloads of popular PC utilities
Microsoft's Windows Defender team has uncovered a cryptocurrency mining campaign targeting PC enthusiasts. Scammers are manipulating search
