A Chinese threat actor has been identified targeting Apple iOS devices using a publicly leaked version of the DarkSword exploit kit. This campaign involves over 100 web properties, many masquerading as fake Amazon Web Services (AWS) sign-in pages, hosted on domains that also serve the exploit toolkit.
The DarkSword exploit kit, first detailed earlier this year, is a full-chain exploit targeting iOS versions 18.4 through 18.7. Initially used by commercial surveillance vendors and suspected state-sponsored actors, DarkSword has been deployed in campaigns against countries including Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025. The kit utilizes watering hole attacks to exploit vulnerabilities in Apple’s mobile operating system, leading to the execution of JavaScript that installs GHOSTBLADE, an information-stealing malware.
Following the public leak of DarkSword’s source code, its usage has expanded among various threat actors. Recent findings indicate that login pages for a panel named “DarkSword Admin” have been identified across multiple hosts in countries such as Hong Kong, Japan, the United States, and Europe. These panels are used by attackers to manage the deployment of the exploit kit and the subsequent exfiltration of stolen data.
The attack sequence typically begins when a victim accesses one of the malicious domains, such as a counterfeit AWS console or Apple ID sign-in page. This triggers a malicious iframe that loads JavaScript, initiating the DarkSword exploit chain and culminating in the deployment of GHOSTBLADE modules. Once installed, GHOSTBLADE extracts sensitive information, including keychain, iCloud, and Wi-Fi credentials, and transmits this data to attacker-controlled servers. The attackers then access the stolen information through various administration panels, such as DarkSword Admin, Decode Dashboard, or C2 Control Panel.
Notably, some of the identified hosts also serve as administration panels for Coruna, an earlier iOS exploit kit targeting versions 3.0 through 17.2.1. Evidence suggests that a threat actor known as UNC6353 has utilized both DarkSword and Coruna in attacks against Ukrainian targets.
This development underscores the persistent threat posed by state-sponsored cyber actors leveraging sophisticated exploit kits to target mobile devices. The public availability of such tools amplifies the risk, enabling a broader range of malicious actors to conduct similar campaigns. Users are advised to keep their devices updated with the latest security patches and exercise caution when accessing unfamiliar websites or entering credentials on unverified platforms.