Back to Feed
Threat IntelligenceMay 5, 2026

New C2 infrastructure and lures detected associated with #Coruna and #DarkSword malware. Threat a...

Coruna and DarkSword malware operators deploy new C2 infrastructure using fake crypto reward lures targeting iOS.

Vendor Watch

Run iOS?

Get an email when a reviewed story names iOS, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

Threat actors behind Coruna and DarkSword malware have established new command-and-control infrastructure and are distributing malicious URLs through fake cryptocurrency reward scam pages. The campaign targets iOS users with remote code execution exploits, combining social engineering with platform-specific vulnerabilities.

Indicators of Compromise

  • malware — Coruna
  • malware — DarkSword

Entities

Coruna operators (threat_actor)DarkSword operators (threat_actor)iOS (product)Command-and-control (C2) (technology)