Researchers identified an exposed Chinese-language environment dubbed Robobox that appears associated with the Coruna/Bee iOS command-and-control ecosystem, an exploit framework previously reverse engineered from its JavaScript components. Hunt.io attack-capture data showed a dashboard and Node.js backend, deployment documentation, mock operational data, a Cobalt Strike team server, a Linux remote-access trojan, and malware-staging services. The exposed instance appears to have been a test or demonstration deployment rather than a confirmed active Coruna operation.
The infrastructure also contained a fake Sogou Pinyin update chain aimed at mainland Chinese users that reportedly served ImageMagik.dll and SGWangzaix.exe. Researchers observed repetitive commands, implementation defects, and React/Vite, backend, and documentation artifacts consistent with AI- or LLM-assisted development and administration, raising concern that operators are testing more autonomous malware creation, reconnaissance, and deployment workflows. The operators' identity, the environment's intended purpose, and whether victims downloaded the staged payloads remain unconfirmed.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
The exposed directory contained a fake Sogou Pinyin update chain assessed as targeting mainland Chinese users and reported to deliver ImageMagik.dll and SGWangzaix.exe. An access log recorded one download of the DLL by a server located in Hong Kong.
The environment hosted a reportedly active Cobalt Strike team server, reachable through r1u1.com, alongside Npcap and scripts for silent installation. Bash history indicated the host installed MySQL and Apache, configured Cobalt Strike, compiled and launched the RAT, and started the Bee iOS C2 framework.
Researchers found a binary named agent that masqueraded as WinPerfDiagSvc but functioned as a Linux RAT labeled as a client for “AI VPS Manager.” The RAT used crontab persistence, encrypted reverse-shell communications, and polled 45.115.124.42:80 via the /api/v3/sync endpoint.
The exposed files included plan.md, info.md, and Deploy.md documents apparently intended to guide an automated system in recreating and deploying the Chinese frontend. Researchers assessed the backend and operational history as showing AI- or LLM-assisted development and administration, while mock data and a mock-up switch suggested the Coruna deployment may have been a test or demonstration rather than a confirmed live operation.
Researchers using Hunt.io attack-capture data identified an exposed Chinese-language environment associated with the Coruna/Bee iOS C2 ecosystem. It included a Bee-like React/Vite dashboard, Node.js backend, device and exploit-chain tracking, and collection functions for wallets, SMS, photos, and other data from compromised iOS devices.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.