Back to Feed
Threat IntelligenceMay 5, 2026

New C2 infrastructure and lures detected associated with #Coruna and #DarkSword malware. Threat a...

Coruna and DarkSword malware operators deploy new C2 infrastructure using fake crypto reward lures targeting iOS.

Summary

Threat actors behind Coruna and DarkSword malware have established new command-and-control infrastructure and are distributing malicious URLs through fake cryptocurrency reward scam pages. The campaign targets iOS users with remote code execution exploits, combining social engineering with platform-specific vulnerabilities.

Indicators of Compromise

  • malware — Coruna
  • malware — DarkSword

Entities

Coruna operators (threat_actor)DarkSword operators (threat_actor)iOS (product)Command-and-control (C2) (technology)