Advanced iOS Spyware Targets Italian iPhone Users via Phishing

Advanced iOS Spyware Targets Italian iPhone Users via Phishing

The rapid evolution of mobile cyber threats has recently reached a critical milestone as Italian citizens find themselves caught in the crosshairs of a highly sophisticated operation that blends traditional deception with cutting-edge technical exploits. This specific campaign exploits the trust individuals place in official state-backed communication platforms, specifically targeting the SEND digital notification service used for government alerts. By meticulously cloning the visual identity and user interface of the pagoPA technology company, attackers have created a deceptive environment that successfully lures unsuspecting iPhone users into a trap. This is not merely a common phishing attempt designed to steal credentials; it represents a coordinated effort to deliver an advanced surveillance payload directly onto the victim’s device without their knowledge. The orchestration of this attack demonstrates a deep understanding of human psychology and the technical limitations of legacy mobile operating systems, highlighting a growing trend where state-level tools are becoming accessible to various threat actors in the digital underground.

Sophisticated Social Engineering and Delivery Mechanisms

Step 1: The Facade of Official Government Communications

Attackers initiate the engagement by directing users to a fraudulent website that mirrors the official SEND government portal with uncanny accuracy, using stolen branding to create an immediate sense of legitimacy. Once a user lands on this malicious domain, they encounter a sophisticated interface that requires manual interaction, including a fake anti-bot verification process designed to lower the target’s guard while building a false sense of security. Following this initial hurdle, the site presents a series of forms that prompt the victim to input highly sensitive personal information, such as their national identification numbers, contact details, and even financial data associated with payment cards. This dual-purpose strategy ensures that even if the technical exploit chain fails to compromise the device, the threat actors still walk away with a significant haul of valuable identity and financial information. The seamless integration of these phishing tactics with the backend exploitation engine marks a departure from simpler attacks, showcasing a level of operational maturity that is increasingly common in contemporary mobile surveillance campaigns.

Step 2: Technical Fingerprinting and Selective Exploitation

While the frontend of the site keeps the user occupied with data entry, a silent and far more dangerous process begins in the background through an invisible iframe that establishes a connection with a separate command server. This backend infrastructure immediately performs a deep fingerprinting of the visitor’s device to determine its exact software version, hardware model, and security configuration without triggering any visible warnings. By analyzing the browser’s user agent and other metadata leaks, the malicious system can identify whether the visitor is using a version of iOS that contains the specific unpatched vulnerabilities required for the next phase of the attack. If the device is found to be running any version between iOS 13 and iOS 17.2.1, the server prepares the delivery of the Coruna Pro V2 toolkit, a specialized exploitation framework. This careful selection process ensures that the attackers do not waste their most valuable exploits on patched devices, thereby reducing the chances of their infrastructure being detected by automated security scanners or research tools.

Anatomy of the Multi-Stage Exploitation Framework

Part 1: Dismantling Security Layers Through Coruna Pro

The exploitation process itself is a masterclass in technical orchestration, consisting of three distinct stages that work in tandem to systematically dismantle the various security protections built into the iOS architecture. The first stage targets known vulnerabilities within the Safari WebKit engine, which is the core component responsible for rendering web content and serves as the primary entry point for the malicious code. By successfully exploiting a memory corruption or logic flaw in WebKit, the attackers gain initial code execution within the context of the browser. This allows them to begin the transition from a standard web session to a more privileged state on the local hardware. Because this initial breach occurs entirely in memory, it leaves a minimal footprint on the device’s storage, making traditional file-based detection methods largely ineffective. The transition from a simple web page to an active exploit runner happens in a matter of seconds, providing the victim with almost no time to react or suspect that their secure mobile environment has been compromised during a routine browsing session.

Part 2: Data Exfiltration and Strategic Defense

Security researchers observed that the effectiveness of this campaign relied heavily on the use of older software versions, as the specific vulnerabilities exploited by the Coruna Pro toolkit were addressed in updates released after the 17.2.1 cycle. Consequently, the primary defense against such advanced threats remained the consistent application of operating system updates as soon as they became available. For individuals who perceived themselves to be at an elevated risk of targeted surveillance, experts recommended the activation of Apple’s Lockdown Mode, which successfully prevented the exploit from executing in monitored test environments. Moving forward, the integration of hardware-backed security and behavioral analysis will be essential in countering the next generation of mobile exploits. Users should establish a habit of verifying government requests through official apps rather than external links. This proactive stance, combined with rigorous digital hygiene, constitutes the most effective barrier against the evolving landscape of sophisticated mobile spyware.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later