'mvt-ios check-fs' positive for coruna
A user reports suspicious activity on multiple Apple devices, including an iPhone scan with the mvt-ios tool detecting a file named 'com.apple.photolibraryd.plist' flagged as associated with the 'Coruna' spyware. The user describes unusual device behavior, interference with evidence capture, and inconsistent analysis results from different tools and helpers. Additional anomalies include hardware issues on a refurbished MacBook, a malicious script detected during a Proton VPN installation attempt, and network device malfunctions. The mvt-ios detection is based on a file name matching known indicators, but the user questions the definitiveness of this finding given the file name matches a legitimate Apple file. No official vendor advisory or patch information is provided.
AI Analysis
Technical Summary
The reported threat involves detection by the mvt-ios tool of a suspicious file named 'com.apple.photolibraryd.plist' on an iPhone, which matches known indicators linked to the 'Coruna' spyware. The detection is based on file name matching against a threat intelligence feed. The user reports multiple unusual device behaviors and inconsistent analysis results, including interference with data capture and network anomalies. The detection tool flagged the file with a high severity level due to its suspicious attributes, such as quarantine and MACL extended attributes uncommon for a daemon's preference file. However, the contents were later interpreted as genuine Photos framework data, leading to uncertainty about the detection's accuracy. No official vendor advisory or patch information is available, and the user expresses doubt about the reliability of the detection given the file name's legitimacy in Apple systems.
Potential Impact
The impact is uncertain due to conflicting interpretations of the detected file. If the detection is accurate, it may indicate the presence of spyware ('Coruna') on the iPhone, potentially compromising device integrity and user privacy. The user also reports broader device instability and suspicious network activity, which could indicate ongoing compromise or interference. However, without confirmed exploitation or vendor confirmation, the actual impact remains speculative.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Given the uncertainty and lack of official confirmation, users should monitor for official updates from Apple or security researchers regarding 'Coruna' spyware. Avoid relying solely on file name-based detections without corroborating evidence. If suspicious activity is suspected, consider professional forensic analysis and device restoration from trusted backups. No specific patch or fix is currently documented.
'mvt-ios check-fs' positive for coruna
Description
A user reports suspicious activity on multiple Apple devices, including an iPhone scan with the mvt-ios tool detecting a file named 'com.apple.photolibraryd.plist' flagged as associated with the 'Coruna' spyware. The user describes unusual device behavior, interference with evidence capture, and inconsistent analysis results from different tools and helpers. Additional anomalies include hardware issues on a refurbished MacBook, a malicious script detected during a Proton VPN installation attempt, and network device malfunctions. The mvt-ios detection is based on a file name matching known indicators, but the user questions the definitiveness of this finding given the file name matches a legitimate Apple file. No official vendor advisory or patch information is provided.
Reddit Discussion
There have been weird things going on with all my electronic devices. They're the kinds of things that, if I were to bother describing them, you would tell me that it is not possible. However, and I am not kidding, every time I captured evidence on my device that would prove the occurrences, the proof would be edited in real time right from my iCloud account (or deleted with no trace of its existence). It may be because I'm involved in sensitive litigation or any other number of things, but I needed proof from outside my device (an external source of validity).
I worked for a while with Claude to try to develop a script to search my iPhone for signs of spyware (I am not a programmer, but it 'he' is a decent one). It would come back positive, but every time he would interpret the results for me, there would be a connection interruption and an API error, and then he would change course and deny the positive result as a false positive. He would then edit the script to soften those specific checks to the point I am not certain they did anything at all. The exact same thing would happen when I asked 'him' to analyze my pcaps. Yesterday, I purchased iMazing. It came back negative for spyware, but that was shortly after a reset.
Last night, I discovered the existence of the mvt tool and performed an 'mvt check-fs' on my iPhone..It came back positive for coruna.
❯ {
"level": "HIGH",
"module": "filesystem",
"message": "Found a known suspicious file name \"com.apple.photolibraryd.plist\" matching indicators from \"Coruna\"",
"event_time": "",
"event": {
"path": "Library/Containers/com.apple.photolibraryd/Data/Library/Preferences/com.apple.photolibraryd.plist",
"modified": "2026-09-12 08:15:19.644263"
},
"matched_indicator": {
"value": "com.apple.photolibraryd.plist",
"type": "file_names",
"name": "Coruna",
"stix2_file_name": "raw.githubusercontent.com_mvt-project_mvt-indicators_main_2026-03-03_coruna_cryptowaters_coruna.stix2"
}
}
]
In typical fashion, when I asked Claude to review the finding, he flags it as suspicious, and even identifies additional suspicious indicators--
"Two things stand out already — the file carries com.apple.quarantine and com.apple.macl extended attributes, which is unusual for a daemon's own preferences file. Let me read those and the contents."
--and then reverses course, such as: "Contents are unambiguously genuine Photos framework data, and the quarantine record names com.apple.cfprefsd as the writing agent. Let me confirm the false-positive mechanism and rule out a real artifact hiding elsewhere."
You get confused and frustrated, like when you have some medical issue but the doctors cannot identify it or its cause.
As another example of bizarre occurrences on another Apple device, I purchased a refurbished MacBook through Amazon last October. Within two months, it began exhibiting hardware issues. It would die to the point that the device did not even have enough energy to display the battery status indicator when attempting to start it, and it would start to recovery mode and warnings that the operating system needed to be reinstalled. The system time would drift from network (real) time. So, I returned it.
I opened back up my old MacBook, which I had replaced because I shorted half the keyboard while cleaning it. It had been wiped since its last use, so after months of being off, it opened to a fresh install. I have always used Proton VPN (or have since 2022), and when I went to install it, the Proton page included instructions to use a curl script to install it. I thought that was weird, but copied and pasted the command to terminal. Within seconds, XProtect grabbed it as running a malicious script. I'm not sure it was fast enough, however. I never saw that page with the curl script again. Proton VPN is downloaded as a dmg file from within your signed-in account. That was not the case that evening.
As anothjer example, on my computer(s), I have had and used Firewalla Gold Plus since 2022. Never had an issue with it. Suddenly, after I received veiled threats for using "firewalls and stuff", my app stopped pairing with it. It was the end of a short sequence of events which began with Firewalla no longer assigning IPv4 addresses to my devices, then assigning IP addresses outside the range of its subnet, and ended with the pairing issue. Long story short, and in the weirdest fashion, I have Firewalla on record spending four days lying to me about the cause, swearing that it is not the security dongle I just paid them $107 to replace, insisting that I open a remote console session, etc., when I used the serial console port and ran some commands to check the status of the HCI controller, the cause was without question, a defective security dongle. Firewalla has always had fantastic tech support. They literally lied to me for four days, trying to get me to open the Remote Support port on a network I repeatedly advised them was unsafe to open it (aside from the fact I couldn't open it without a paired device).
As another, I will suddenly get a warning that my memory is almost used up. Safari will be using 4-8 Gigs of RAM. That RAM will ostensibly be supporting the four tabs it has open, none of which run persistent programs that use high amounts of RAM. I'll look at my application layer firewall, Little Snitch, and it will have 1,000+ incoming connections. I'll copy the list and ask Claude to advise, "They're all benign, see a psychiatrist." Whether they're benign is a separate issue from the fact that it has never happened before, and ALF and Little Snitch both are set to deny all incoming connections by default. I shouldn't even be able to see these attempted connections in anything by the "denied" list (or not at all, since ALF doesn't have one). They’re requesting to connect with my devices around three firewall layers (one hardware, two application layers).
These weird things stack up and become oppressively heavy, and you just want affirmative answers.
I hoped this would help identify the issue with my iPhone so I could move forward with identifying the potential remedy.
How definitive is the ‘mvt-ios check-fs’ command?
If the file it identified shares its name with a genuine, Apple-published file, why would mvt recommend spending thousands of dollars on a forensic IT specialist based on name identification alone? Wouldn’t every iPhone in use have a false positive?
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The reported threat involves detection by the mvt-ios tool of a suspicious file named 'com.apple.photolibraryd.plist' on an iPhone, which matches known indicators linked to the 'Coruna' spyware. The detection is based on file name matching against a threat intelligence feed. The user reports multiple unusual device behaviors and inconsistent analysis results, including interference with data capture and network anomalies. The detection tool flagged the file with a high severity level due to its suspicious attributes, such as quarantine and MACL extended attributes uncommon for a daemon's preference file. However, the contents were later interpreted as genuine Photos framework data, leading to uncertainty about the detection's accuracy. No official vendor advisory or patch information is available, and the user expresses doubt about the reliability of the detection given the file name's legitimacy in Apple systems.
Potential Impact
The impact is uncertain due to conflicting interpretations of the detected file. If the detection is accurate, it may indicate the presence of spyware ('Coruna') on the iPhone, potentially compromising device integrity and user privacy. The user also reports broader device instability and suspicious network activity, which could indicate ongoing compromise or interference. However, without confirmed exploitation or vendor confirmation, the actual impact remains speculative.
Defensive Guidance
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Given the uncertainty and lack of official confirmation, users should monitor for official updates from Apple or security researchers regarding 'Coruna' spyware. Avoid relying solely on file name-based detections without corroborating evidence. If suspicious activity is suspected, consider professional forensic analysis and device restoration from trusted backups. No specific patch or fix is currently documented.
Technical Details
- Source Type
- Subreddit
- cybersecurity
- Reddit Score
- 0
- Discussion Level
- minimal
- Content Source
- reddit_link_post
- Post Type
- link
- Newsworthiness Assessment
- {"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true}
- Has External Source
- true
- Trusted Domain
- false
Threat ID: 6aa5856855bf5e2cf585d032
Added to database: 09/12/2026, 17:01:28 UTC
Last enriched: 09/12/2026, 17:01:35 UTC
Last updated: 09/13/2026, 03:01:31 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.