Threat IntelligenceMay 5, 2026
New C2 infrastructure and lures detected associated with #Coruna and #DarkSword malware. Threat a...
Coruna and DarkSword malware operators deploy new C2 infrastructure using fake crypto reward lures targeting iOS.
Vendor Watch
Run iOS?
Get an email when a reviewed story names iOS, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Threat actors behind Coruna and DarkSword malware have established new command-and-control infrastructure and are distributing malicious URLs through fake cryptocurrency reward scam pages. The campaign targets iOS users with remote code execution exploits, combining social engineering with platform-specific vulnerabilities.
Indicators of Compromise
- malware — Coruna
- malware — DarkSword
Entities
Coruna operators (threat_actor)DarkSword operators (threat_actor)iOS (product)Command-and-control (C2) (technology)