An emergent cyber threat has been identified, with a Chinese threat actor reportedly using the leaked DarkSword exploit kit to target Apple iOS devices. This campaign has been highlighted by Censys, a platform specializing in attack surface management, which noted that over 100 fake web pages resembling Amazon Web Services (AWS) sign-in pages are involved in this malicious activity.
Scope of the DarkSword Exploit Kit
According to Censys researcher Aidan Holland, these web properties are strategically hosted in Hong Kong, reaching users in Japan, the United States, and Europe. The DarkSword exploit kit, first brought to light by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, is a comprehensive tool for cyber assaults. Used in prior attacks on various nations since late 2025, the kit has now surfaced again due to the public leak of its source code, inviting new malicious actors to exploit it.
DarkSword targets iOS versions 18.4 through 18.7, using watering holes to initiate now-resolved vulnerabilities in Apple’s systems. This process leads to the execution of JavaScript, which facilitates the deployment of GHOSTBLADE, an information-stealing malware.
Details of the Exploit Operations
The latest findings reveal that the DarkSword Admin panel, linked to seven host sites in three countries as of July 30, 2026, is part of this exploit. In particular, a Singapore-based host has been identified along with a Hong Kong host that acts as a decoy for Apple ID credentials. Additionally, there are six other IP addresses involved, indicating a widespread and coordinated effort.
Victims are typically lured to these malicious domains, where a deceptive iframe loads JavaScript to launch the DarkSword chain, culminating in GHOSTBLADE deployment. The malware then extracts sensitive information such as keychain, iCloud, and Wi-Fi credentials, transmitting the data to attacker-controlled locations.
Impact and Future Implications
This campaign’s breadth and the use of shared components from the leaked source code indicate a sophisticated level of planning and execution. Notably, a Singaporean host was found to host Coruna, an earlier exploit kit targeting older iOS versions, suggesting a potential link with the threat actor UNC6353, particularly in attacks on Ukrainian targets.
Censys also uncovered an open directory in Frankfurt exposing tools used by the operators, including references to Thorn C2, a previously undocumented malware. This discovery, coupled with the distinctive design of the C2 Control Panel interface, highlights the complex nature of this cyber threat.
The ongoing investigation into this threat underscores the critical need for vigilance in cybersecurity practices, particularly for entities vulnerable to such sophisticated exploit kits. The use of leaked resources like DarkSword poses a significant risk, signaling the importance of robust security measures to counteract these evolving threats.
