Policy & Regulation
L3Harris hacking tools likely used in global surveillance campaigns
A mass hacking campaign targeting iPhone users in Ukraine and China likely used surveillance tools developed by U.S. military contractor L3Harris.
Over the course of 2025, Google discovered that an iPhone-hacking toolkit had been used in a series of global attacks. The toolkit, named Coruna, consisted of 23 different components. According to TechCrunch, a mass hacking campaign targeting iPhone users in Ukraine and China used tools that were likely designed by U.S. military contractor L3Harris. The tools wound up in the hands of various hacking groups, including Russian government spooks and Chinese cybercriminals. Two former employees of government contractor L3Harris stated that Coruna was, at least in part, developed by Trenchant, the company’s hacking and surveillance tech division. L3Harris sold Trenchant’s tools exclusively to the U.S. government and its allies in the Five Eyes (an intelligence alliance including Australia, Canada, New Zealand, and the United Kingdom).
The proliferation of these tools is linked to Peter Williams, a 39-year-old former Trenchant general manager. Williams sold eight company hacking tools to Operation Zero, a Russian company that buys zero-day exploits (vulnerabilities that are unknown to the affected vendor), for $1.3 million. Williams was sentenced to seven years in prison after he admitted to the sales, with the U.S. government stating he betrayed the United States and its allies. The U.S. Treasury alleged that the Russian broker sold the stolen tools to at least one unauthorized user, which may explain how a Russian espionage group acquired Coruna to target users in Ukraine. Williams also recognized code he wrote and sold to Operation Zero later being used by a South Korean broker.
Researchers at mobile cybersecurity company iVerify suggest that Coruna may have been originally built by a company that sold it to the U.S. government. Technical analysis links Coruna to Operation Triangulation (a sophisticated hacking campaign first revealed by Kaspersky in 2023). Rocky Cole, co-founder of iVerify, said the assessment is “the best explanation based on what’s known right now” regarding the tools’ origins. This assessment is supported by the timeline of Williams’ leaks and technical similarities to Operation Triangulation. Additionally, a former Trenchant employee noted that when Kaspersky first revealed the campaign in 2023, colleagues believed at least one of the zero-day exploits caught by the security firm came from their internal project. Other clues pointing to Trenchant include the use of bird names for the tools, reminiscent of a tool sold to the FBI for the San Bernardino iPhone cracking case.
Why it matters
The revelation that a U.S. military contractor’s hacking tools were likely used in global surveillance campaigns highlights the severe risks of government-developed cyber weapons falling into the hands of unauthorized actors.