At a Glance
| Attribute | Details |
|---|---|
| Malware Family | Coruna Pro V2 (modified variant) |
| Threat Actor | Unknown (Telegram handle: @ojishu) |
| Target Victims | Italian citizens and businesses using older iPhones |
| Delivery Vector | Fake SEND digital notification portal via SMS/email links |
| Key Capabilities | WebKit exploitation, sandbox escape, data theft (SMS, photos, contacts) |
| Source | D3Lab |
Executive Summary
Cybercriminals launched a deceptive operation that targets mobile users in Italy. They created a highly convincing replica of the national notification portal, SEND. However, this is not a typical data-theft site. Behind the scenes, the site runs an automated hacking sequence against Safari. D3Lab stated, “Based on D3Lab’s observations in the Italian threat landscape, this is the first time we have documented an iOS chain of this kind embedded in a conventional phishing campaign targeting Italy.”
Deceptive Delivery Tactics
The attack begins when a victim receives a fake notification claiming they have a pending legal or administrative document. The message directs the victim to a website designed to look exactly like the pagoPA SEND portal. Because SEND delivers official government notices, victims feel a strong sense of urgency to click the link.
When the user opens the page, they encounter a fake anti-bot check. Once the victim clicks to proceed, the page reloads and displays the fraudulent SEND interface. This frontend uses Socket.IO to communicate with the attacker in real time. This means the fraudster can dynamically alter the questions asked, requesting credit card details or verification codes depending on the victim’s responses.
The Invisible Infection Chain
While the victim interacts with the fake SEND portal, a dangerous process runs invisibly in the background. The webpage contains a hidden iframe that connects to a separate exploitation server. D3Lab researchers explained, “The victim does not need to deliberately install an application or open an attachment: the browser itself becomes the entry point.”
The exploit server delivers a sophisticated three-stage attack against the Safari browser engine (WebKit). The system first fingerprints the victim’s device to determine the iOS version. It supports devices running iOS 13 through iOS 17.2.1.
If the device is vulnerable, the first stage attempts to gain memory read-and-write permissions. The second stage targets devices equipped with Pointer Authentication Codes (PAC) to bypass hardware protections. Finally, the third stage attempts to escape the Safari sandbox entirely. Escaping the sandbox allows the attacker’s code to interact with the underlying operating system and other applications freely.
Command-and-Control and Data Exfiltration
If the exploit chain succeeds, the post-exploitation module begins harvesting extensive personal data. The malware targets SMS databases, call histories, address books, Safari bookmarks, and location histories. The attack even specifically targets the iOS Keychain, which stores saved passwords.
The collected data is then transmitted to a centralized command-and-control server. The infrastructure features a detailed management panel written in Chinese, titled “Lü Technology Console API.” The panel allows operators to manage infected devices, view exfiltrated data, and link compromised WhatsApp accounts.
Security analysts discovered a Telegram handle, “@ojishu”, embedded directly in the server’s control panel. Despite the Chinese language interface and the Telegram handle, researchers cannot definitively attribute the attack to a specific nation-state.
The exploit kit itself appears to be a heavily modified version of a public research toolkit called Coruna Pro V2. The operators added custom crash handling, telemetry gathering, and remote command execution features to the original codebase.
Defense and Detection Guidance
This campaign proves that merely visiting a website can compromise an outdated smartphone. Fortunately, the exploit chain cannot infect iPhones running iOS versions newer than 17.2.1. Therefore, installing the latest Apple software updates is the most effective defense against this attack.
Users must remain vigilant when receiving administrative notifications. The official Italian citizen portal is located at cittadini.notifichedigitali.it and requires secure digital identity authentication. High-risk individuals should consider enabling Apple’s Lockdown Mode, which severely restricts browser capabilities to block similar web-based exploits. Never trust urgent messages demanding immediate action, even if they appear to come from government authorities.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!