An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.
Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit.
“The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe,” Censys researcher Aidan Holland said in an analysis published on July 31, 2026.
DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.
The kit, which specifically targets iOS versions 18.4 through 18.7, has been observed to employ watering holes as a starting point to trigger now-patched vulnerabilities in Apple’s mobile operating system to execute JavaScript that ultimately facilitates the deployment of GHOSTBLADE, an information-stealing malware.
The latest findings from Censys show that the login page for a panel called “DarkSword Admin” matches seven hosts across three countries as of July 30, 2026, in addition to a Singapore-based host (“38.181.52[.]95”) running three distinct exploit-panel front ends and a Hong Kong host that bundles an Apple ID credential-harvesting decoy (“103.106.190[.]217”).
One such login panel served on the IP address “38.22.89[.]117:8888” contains Chinese-language field labels for “username,” “password,” and “Log in.” The other six IP addresses are below –
The attack flow is fairly consistent in that it begins when a victim reaches one of the operator’s domains – an AWS-console impersonation subdomain or an Apple ID sign-in page – causing a malicious iframe element to load JavaScript that fires the DarkSword chain and finally deploys GHOSTBLADE modules.
On successful exploitation, the implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules and commences the file-exfiltration sweep. The harvested data is then packaged and transmitted to attacker-controlled endpoints. The attacker then logs in to one of the panels, namely DarkSword Admin, Decode Dashboard, or C2 Control Panel, to extract the pilfered data.
“This cluster runs the leaked kit rather than a reimplementation, and the evidence is a shared staging-page hash plus Russian-language code comments carried over from the leaked source,” Holland said.
Leave a Reply