Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Posted on August 3, 2026 By CWS

An emergent cyber threat has been identified, with a Chinese threat actor reportedly using the leaked DarkSword exploit kit to target Apple iOS devices. This campaign has been highlighted by Censys, a platform specializing in attack surface management, which noted that over 100 fake web pages resembling Amazon Web Services (AWS) sign-in pages are involved in this malicious activity.

Scope of the DarkSword Exploit Kit

According to Censys researcher Aidan Holland, these web properties are strategically hosted in Hong Kong, reaching users in Japan, the United States, and Europe. The DarkSword exploit kit, first brought to light by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, is a comprehensive tool for cyber assaults. Used in prior attacks on various nations since late 2025, the kit has now surfaced again due to the public leak of its source code, inviting new malicious actors to exploit it.

DarkSword targets iOS versions 18.4 through 18.7, using watering holes to initiate now-resolved vulnerabilities in Apple’s systems. This process leads to the execution of JavaScript, which facilitates the deployment of GHOSTBLADE, an information-stealing malware.

Details of the Exploit Operations

The latest findings reveal that the DarkSword Admin panel, linked to seven host sites in three countries as of July 30, 2026, is part of this exploit. In particular, a Singapore-based host has been identified along with a Hong Kong host that acts as a decoy for Apple ID credentials. Additionally, there are six other IP addresses involved, indicating a widespread and coordinated effort.

Victims are typically lured to these malicious domains, where a deceptive iframe loads JavaScript to launch the DarkSword chain, culminating in GHOSTBLADE deployment. The malware then extracts sensitive information such as keychain, iCloud, and Wi-Fi credentials, transmitting the data to attacker-controlled locations.

Impact and Future Implications

This campaign’s breadth and the use of shared components from the leaked source code indicate a sophisticated level of planning and execution. Notably, a Singaporean host was found to host Coruna, an earlier exploit kit targeting older iOS versions, suggesting a potential link with the threat actor UNC6353, particularly in attacks on Ukrainian targets.

Censys also uncovered an open directory in Frankfurt exposing tools used by the operators, including references to Thorn C2, a previously undocumented malware. This discovery, coupled with the distinctive design of the C2 Control Panel interface, highlights the complex nature of this cyber threat.

The ongoing investigation into this threat underscores the critical need for vigilance in cybersecurity practices, particularly for entities vulnerable to such sophisticated exploit kits. The use of leaked resources like DarkSword poses a significant risk, signaling the importance of robust security measures to counteract these evolving threats.

The Hacker News Tags:Apple vulnerabilities, AWS phishing, Censys, Chinese threat actor, cyber espionage, cyber threats, Cybersecurity, DarkSword, exploit kits, GHOSTBLADE, information theft, iOS attacks, Malware, mobile security

Post navigation

Previous Post: XCSSET v40 Targets macOS Devs via Compromised Xcode
Next Post: SonicWall Vulnerabilities Exploited in Ransomware Surge

Related Posts

Russian Hackers Leverage Microsoft OWA Vulnerability Russian Hackers Leverage Microsoft OWA Vulnerability The Hacker News
Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme Critical Exploit Lets Hackers Bypass Authentication in WordPress Service Finder Theme The Hacker News
SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and More SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and More The Hacker News
Rethinking AI Data Security: A Buyer’s Guide  Rethinking AI Data Security: A Buyer’s Guide  The Hacker News
Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code Malicious VS Code AI Extensions with 1.5 Million Installs Steal Developer Source Code The Hacker News
npm 12 Enhances Security by Disabling Install Scripts npm 12 Enhances Security by Disabling Install Scripts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • N-able Releases Patch for Exploited N-central Vulnerability
  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • N-able Releases Patch for Exploited N-central Vulnerability
  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark