Chinese-Speaking Threat Actor Leverages Leaked DarkSword Exploit Kit Against iOS Users
A Chinese-speaking threat actor is actively exploiting a publicly leaked version of the **DarkSword** exploit kit to target **Apple iOS** devices. This campaign, identified by **Censys**, involves over 100 malicious web properties, primarily fake **Amazon Web Services (AWS)** login pages, designed to deploy the **GHOSTBLADE** information-stealing malware.
An unknown Chinese-speaking threat actor has been observed running a campaign targeting **Apple iOS** devices by leveraging a publicly leaked version of the **DarkSword** exploit kit.
Attack surface management platform **Censys** identified the threat actor operating more than 100 web properties. Most of these are fake **Amazon Web Services (AWS)** sign-in pages hosted on domains that also host the exploit toolkit.
"The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe," **Censys** researcher **Aidan Holland** stated in an analysis published on July 31, 2026.
**DarkSword**, initially discovered and detailed earlier this year by **Google Threat Intelligence Group (GTIG)**, **iVerify**, and **Lookout**, is a full-chain exploit kit. It is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in various campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.
### Targeting iOS 18.4 through 18.7
The kit specifically targets **iOS** versions 18.4 through 18.7. It employs watering hole attacks to trigger now-patched vulnerabilities in **Apple's** mobile operating system, executing JavaScript that ultimately deploys **GHOSTBLADE**, an information-stealing malware.
The use of **DarkSword** has expanded significantly following a public leak of its source code on **GitHub**, prompting other threat actors to adopt the exploit.
### Exploit Panel Sprawl
Latest findings from **Censys** reveal that the login page for a panel named "DarkSword Admin" matches seven hosts across three countries as of July 30, 2026. This includes a Singapore-based host ("38.181.52[.]95") running three distinct exploit-panel front ends and a Hong Kong host bundling an **Apple ID** credential-harvesting decoy ("103.106.190[.]217").
One such login panel, served on the IP address "38.22.89[.]117:8888," contains Chinese-language field labels for "username," "password," and "Log in." The other six identified IP addresses are:
* 103.97.128[.]67:8888
* 162.4.136[.]30:8888
* 223.26.63[.]56:8888
* 151.243.126[.]191:8888
* 107.175.49[.]181:3000
* 103.238.129[.]112:3000
### Attack Flow and Data Exfiltration
The attack flow consistently begins when a victim accesses one of the operator's domains β either an **AWS** console impersonation subdomain or an **Apple ID** sign-in page. This action causes a malicious iframe element to load JavaScript, which triggers the **DarkSword** exploit chain and ultimately deploys **GHOSTBLADE** modules.

Upon successful exploitation, the implant delivers modules for dumping keychain, **iCloud**, and Wi-Fi credentials, then initiates a file-exfiltration sweep. The harvested data is packaged and sent to attacker-controlled endpoints. The attacker then logs into one of the panels, such as **DarkSword Admin**, "Decode Dashboard," or "C2 Control Panel," to retrieve the pilfered data.
IP addresses associated with the other login panels include:
* 103.226.155[.]200 (Decode Dashboard)
* 103.226.155[.]201 (Decode Dashboard)
* 202.8.120[.]249 (Decode Dashboard)
* 103.106.190[.]217 (C2 Control Panel), which also co-hosts the **Apple ID** decoy sign-in page
"This cluster runs the leaked kit rather than a reimplementation, and the evidence is a shared staging-page hash plus Russian-language code comments carried over from the leaked source," Holland explained.
### Links to Other Exploits and Malware
Furthermore, the Singaporean host (now inactive) was found to host an administration panel for **Coruna**, another **iOS** exploit kit that predates **DarkSword** and targets **iOS** versions 3.0 through 17.2.1. Evidence suggests that a threat actor known as **UNC6353** has leveraged both exploit kits in attacks against Ukrainian targets.
**Censys** also uncovered an open directory listing in Frankfurt ("93.152.221[.]37") exposing the operator's tooling. This included an **SSH** key comment "jkcing@apt," a web-content fuzzer, and references to a previously undocumented malware family called "Thorn C2."
"The 'C2 Control Panel' login itself is a visually distinct build from the other two panels: a near-black #06060d background, a #ff0050 red accent, an animated particle-canvas effect, a group name rendered directly on the page (δΊε€ͺιε’, 'Asia-Pacific Group'), and a visible Telegram contact link, hxxps://t[.]me/YATA0000," the report noted. "That's the first direct contact channel we've recovered for this operator; the other panels give us a login gate and nothing else."
