All Newsletters

Valid Points · March 2026

Tracking Coruna and DarkSword Proliferation

Tracking Coruna and DarkSword exploit kits with Validin and announcing webhook support.

Welcome back to Validin’s monthly newsletter and thank you for inviting us into your inbox. This month we tracked the proliferation of two advanced exploit kits targeting iPhones used by financially-motivated threat actors: Coruna, which led to the discovery of DarkSword. We’re also excited to announce webhooks for real-time events for Validin data. As always, we appreciate any feedback! - The Validin Team

aye-coruna-validin

RESEARCH BLOG

💬 Aye-Coruna: Tracing the iOS Exploit Kit from Ukraine to Iran War Lures

On March 3, 2026, the Google Threat Intelligence Group (GTIG) and the iVerify Team detailed findings related to an exploit kit targeting Apple iPhone users nicknamed “Coruna.” The Validin team used the indicators from those reports to find significant additional proliferation of Coruna and track the C2 domains used for reconnaissance.

Less than two weeks later, the Lookout team used Validin to discover two compromised Ukrainian domain names hosting a similar exploit kit targeting newer iPhone versions, dubbed DarkSword. Read the additional write-ups of DarkSword by GTIG and the iVerify Team.

👉 Read the Validin blog about Coruna now.

webhooks-validin

IN CASE YOU MISSED IT

Validin introduces support for Webhooks

Ingest data from Validin directly in your environments with Validin Webhooks.

Read the complete blog here

misp-integration-yara-validin

Validin MISP Integration

Validin is expanding its integration capabilities with support for MISP. Learn more about how to use Validin as an enrichment in your MISP environments here

pivotcon-2026

👋 See you in Spain

We are excited to announce our continued support as a Gold Sponsor of PIVOTcon, an event that focuses on threat research and technical analysis tradecraft. We attended last year and are excited to return to Malaga, Spain as attendees.

Learn more about PIVOTcon

SPOT VALIDIN IN...

📰 NBC News | He was a perfect hire — until a U.S. company exposed him as a likely North Korean operative

Validin was cited in an NBC News exposé about North Korean IT workers, referencing fake job posting pages. Read their article here. Also find our original research here.

📺 60 Minutes Australia | Kim Jong Un’s North Korean spies hiding in plain sight

60 Minutes Australia recently conducted its own investigation into North Korean IT workers posing as US-based remote workers to infiltrate Australian companies. Watch the full investigation.

💳 Shadowserver Foundation introduces new feed of ClickFix/Clearfake compromised websites

In collaboration with Alliance partners and Validin, the Shadowserver Foundation has added a feed of IPs and domains that are compromised by ClickFix malware, prompting users to install malware with injected JavaScript. Read the report now.

BY THE NUMBERS

Top Viewed Threat Actor Profiles and their position change from last month. If you're logged into Validin, view the full profiles:

  1. Lazarus Group

  2. Fake Software Downloads (new)
  3. Muddywater (new)
  4. ClickFix
  5. Kimsuky (new)

Get in touch

Contact us

Validin is the first tab I open every morning.
Senior Analyst, Financial Services IT Company