Valid Points · March 2026
Tracking Coruna and DarkSword Proliferation
Tracking Coruna and DarkSword exploit kits with Validin and announcing webhook support.
Welcome back to Validin’s monthly newsletter and thank you for inviting us into your inbox. This month we tracked the proliferation of two advanced exploit kits targeting iPhones used by financially-motivated threat actors: Coruna, which led to the discovery of DarkSword. We’re also excited to announce webhooks for real-time events for Validin data. As always, we appreciate any feedback! - The Validin Team
RESEARCH BLOG
💬 Aye-Coruna: Tracing the iOS Exploit Kit from Ukraine to Iran War Lures
On March 3, 2026, the Google Threat Intelligence Group (GTIG) and the iVerify Team detailed findings related to an exploit kit targeting Apple iPhone users nicknamed “Coruna.” The Validin team used the indicators from those reports to find significant additional proliferation of Coruna and track the C2 domains used for reconnaissance.
Less than two weeks later, the Lookout team used Validin to discover two compromised Ukrainian domain names hosting a similar exploit kit targeting newer iPhone versions, dubbed DarkSword. Read the additional write-ups of DarkSword by GTIG and the iVerify Team.

IN CASE YOU MISSED IT
Validin introduces support for Webhooks
Ingest data from Validin directly in your environments with Validin Webhooks.
Validin MISP Integration
Validin is expanding its integration capabilities with support for MISP. Learn more about how to use Validin as an enrichment in your MISP environments here
👋 See you in Spain
We are excited to announce our continued support as a Gold Sponsor of PIVOTcon, an event that focuses on threat research and technical analysis tradecraft. We attended last year and are excited to return to Malaga, Spain as attendees.
SPOT VALIDIN IN...
📰 NBC News | He was a perfect hire — until a U.S. company exposed him as a likely North Korean operative
Validin was cited in an NBC News exposé about North Korean IT workers, referencing fake job posting pages. Read their article here. Also find our original research here.
📺 60 Minutes Australia | Kim Jong Un’s North Korean spies hiding in plain sight
60 Minutes Australia recently conducted its own investigation into North Korean IT workers posing as US-based remote workers to infiltrate Australian companies. Watch the full investigation.
💳 Shadowserver Foundation introduces new feed of ClickFix/Clearfake compromised websites
In collaboration with Alliance partners and Validin, the Shadowserver Foundation has added a feed of IPs and domains that are compromised by ClickFix malware, prompting users to install malware with injected JavaScript. Read the report now.
BY THE NUMBERS
Top Viewed Threat Actor Profiles and their position change from last month. If you're logged into Validin, view the full profiles:
- Fake Software Downloads (new)
- Muddywater (new)
- ClickFix
- Kimsuky (new)
Get in touch
Contact us
Validin is the first tab I open every morning.