A Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices using a publicly leaked version of the DarkSword exploit kit, according to attack surface management company Censys.
Researchers discovered more than 100 web properties linked to the operation. Many of the sites were disguised as Amazon Web Services (AWS) login pages or Apple ID sign-in portals. The infrastructure is mainly hosted in Hong Kong, with additional servers identified in Japan, the United States, Europe, and Singapore.
DarkSword is a full-chain iOS exploit kit designed to compromise Apple devices through multiple vulnerabilities. The toolkit targets iOS versions 18.4 through 18.7 and has previously been linked to campaigns involving commercial spyware vendors and suspected state-backed groups.
The attack begins when a victim visits a malicious website controlled by the attacker. The page loads a hidden iframe that executes JavaScript and triggers the DarkSword exploit chain. After successful exploitation, the attacker deploys GHOSTBLADE, an information-stealing malware implant designed to collect sensitive data from compromised devices.
GHOSTBLADE modules can extract information such as Keychain credentials, iCloud data, Wi-Fi passwords, and local files. The stolen data is collected, packaged, and sent to attacker-controlled servers, where operators can access it through management panels.
Censys discovered multiple DarkSword administration panels. One panel hosted at an IP address linked to Singapore contained Chinese-language login fields for usernames, passwords, and authentication. Another Hong Kong-based server hosted an Apple ID credential-harvesting page used as a decoy.
Researchers found evidence that the attackers are using the leaked DarkSword source code rather than developing a new exploit framework. Indicators include shared staging-page hashes and Russian-language comments left inside the leaked code.
The same infrastructure also showed connections to another iOS exploit kit called Coruna, which targets older iOS versions from 3.0 through 17.2.1. Censys noted possible links between the tools and a threat group tracked as UNC6353, which has been associated with attacks targeting Ukrainian organizations.
Further analysis uncovered an exposed directory on a Frankfurt-based server containing attacker tools, including an SSH key comment referencing “apt,” a web-content fuzzing tool, and references to a previously unknown malware family called Thorn C2.