Skip to content
Beveiligingsnieuws

Leaked DarkSword Kit powers iOS GHOSTBLADE attacks

DarkSword iOS-exploitketen

Security researchers have linked a campaign against Apple iOS devices to a Leaked DarkSword kit that was made public after its source code exposure. Observations by Censys indicate that the operator is running the toolkit from a cluster of web properties, including large numbers of fake sign-in pages designed to lure victims into loading malicious content.

At the heart of the activity is an exploit chain that leads to the delivery of GHOSTBLADE, an information-stealing malware. What makes this case especially concerning is how quickly leaked exploit components can be adopted, allowing different actors to reuse the same foothold and infrastructure patterns.

DarkSword exploit chain and why it matters

DarkSword is described as a full-chain exploit kit discovered earlier in 2026 by multiple threat-intelligence teams, including Google Threat Intelligence Group, iVerify, and Lookout. According to the findings, the kit has been associated with campaigns targeting multiple regions, including Saudi Arabia, Turkey, Malaysia, and Ukraine, starting at least as early as November 2025.

The key technical detail is that DarkSword focuses on specific iOS versions—18.4 through 18.7. Instead of delivering malware directly, the toolkit first triggers vulnerabilities in Apple’s mobile operating system and then executes JavaScript that ultimately enables the installation of GHOSTBLADE modules.

From watering holes to JavaScript execution

Censys reports that the operation often begins with a victim visiting one of the operator-controlled domains. In many cases, this involves watering holes as the starting point—malicious entry points that can quietly route visitors toward exploitation paths.

Once the victim lands on the attacker’s domain, the flow uses malicious web content—such as an iframe—to load JavaScript. That JavaScript then activates the DarkSword exploitation chain, which in turn facilitates the final step: deployment of GHOSTBLADE.

This is an important shift from purely “one-step” phishing. Here, the fake landing pages and the exploit tooling work together: the lure gets the victim to the right place, and the exploit chain carries out the compromise.

Fake AWS and Apple login pages as lures

Attack surface management provider Censys says it identified the threat actor running more than 100 web properties. Most of these are described as fake Amazon Web Services (AWS) sign-in pages hosted on domains that also include the exploit kit infrastructure.

The hosting concentrates in Hong Kong but appears to reach into other regions, including Japan, the United States, and Europe. The combination suggests an infrastructure strategy aimed at both availability and operational flexibility.

In addition to the AWS impersonation subdomains, the campaign also includes domains impersonating Apple ID sign-in pages. These pages act as a gateway for the exploit flow, often paired with decoy elements that mimic the expected login interface.

What Censys found inside the operator’s panels

Beyond the lure pages, Censys tied the cluster to a set of administration interfaces related to the DarkSword operation. Specifically, the login for a panel named “DarkSword Admin” was reported to match across seven hosts in three countries as of July 30, 2026.

The same activity also includes a Singapore-based host—now no longer active—that previously served multiple front ends. Censys also notes that one Hong Kong-hosted system bundles an Apple ID credential-harvesting decoy alongside the operator’s command-and-control panel.

Credential-harvesting decoy and localized UI

One of the observed login panels—reachable via an IP address and port combination—contains Chinese-language field labels for username, password, and Log in. While this does not confirm every part of the compromise happens through direct credential capture, it does show the social-engineering layer is tailored to language and presentation.

Censys lists the related panel IPs used for the operator interfaces, including addresses serving the “DarkSword Admin” login as well as other panels described below.

GHOSTBLADE payload behavior after successful exploitation

When exploitation succeeds, the implant described as GHOSTBLADE begins collecting sensitive information. Censys reports that the modules focus on high-value targets such as:

  • Keychain data
  • iCloud related credential material
  • Wi‑Fi credential dumping
  • File-exfiltration sweeps

After the harvesting phase, the data is packaged and sent to attacker-controlled endpoints. The operator then uses one of the available panels to extract what was collected—most notably DarkSword Admin, Decode Dashboard, or a C2 Control Panel interface.

This panel-based workflow highlights an operational pattern: compromise first, then data handling and retrieval through a separate interface layer that can be updated and managed.

Shared evidence suggests reuse of the leaked source

Censys emphasizes that the observed cluster runs the leaked toolkit rather than rebuilding it from scratch. Two forms of shared evidence are cited: a shared staging-page hash and Russian-language code comments preserved from the leaked source.

These indicators help explain why the activity looks consistent across the operator’s infrastructure. Instead of improvising new exploit logic, the actor appears to reuse the leaked components directly.

Since the public leak of the source code, Censys notes that other threat actors may have joined exploitation efforts, lowering the barrier to entry for malicious campaigns.

Other iOS exploit kit references and possible overlap

In addition to DarkSword, Censys observed that the (now inactive) Singapore host once hosted an administration panel for Coruna, an iOS exploit kit that predates DarkSword. Coruna is described as targeting iOS versions 3.0 through 17.2.1.

There is also some evidence suggesting a threat actor known as UNC6353 may have leveraged both exploit kits in attacks aimed at Ukrainian targets. While this does not confirm a single operator for every case, it suggests an environment where multiple exploit toolchains can be combined across campaigns.

One C2 panel that exposes clearer operator contact

Censys also describes differences between the panels. The C2 Control Panel login page was noted as visually distinct compared with the other interfaces. It includes a near-black background, a bright red accent, an animated particle-canvas effect, and a group name rendered directly on the page.

Most notably, the C2 Control Panel includes a visible Telegram contact link. Censys calls this the first direct communication channel recovered for the operator, whereas the other panels primarily serve as login gates without additional visible contact options.

Practical takeaways for iOS security

Cases like this underline a broader pattern: leaked exploit code accelerates real-world harm. Even when the underlying vulnerability is tied to a specific iOS version range, the surrounding infrastructure—fake sign-in pages, malicious web content, and panel-based data retrieval—remains usable and adaptable.

If you manage Apple devices, the most effective defense remains staying current with security updates and ensuring endpoints can validate legitimate sign-in flows. For organizations, it also helps to watch for suspicious web resources that resemble cloud or Apple authentication pages, especially when accompanied by unexpected redirections and embedded frames.

Conclusion

The observed campaign shows how a Leaked DarkSword kit can be repackaged into a functioning iOS threat pipeline. By combining exploit delivery with convincing AWS-console and Apple ID sign-in lures, the operator can trigger JavaScript execution, compromise iOS 18.4–18.7 devices, and deploy GHOSTBLADE to steal credentials and exfiltrate files. For defenders, the key lesson is that public exploit leaks shorten the time between vulnerability knowledge and active exploitation—and they expand the set of actors capable of launching attacks.

Source: https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html