DarkSword iOS Exploit Kit Targets iPhones via Expanding Web Infrastructure

The DarkSword iOS exploit kit has evolved into a rapidly expanding network of malicious web infrastructure, targeting iPhones running iOS versions 18.4 through 18.7. This campaign aims to steal sensitive data by luring victims to compromised websites.

Initially, users are directed to deceptive sign-in pages, iOS-themed sites, or compromised web properties that discreetly load the exploit chain. Once activated, DarkSword bypasses device protections, accesses personal data, and deploys GHOSTBLADE modules designed to extract keychain information, iCloud data, Wi-Fi credentials, and other sensitive files.

Researchers at Censys have been monitoring this infrastructure’s growth by identifying consistent web-page fingerprints across rapidly changing hosts and domains. Their analysis reveals that the operators frequently replace servers within days while maintaining recognizable panel and staging-page content. As of July 30, 2026, Censys observed 27 hosts and 180 web properties associated with DarkSword, though this number is continually changing.

DarkSword is a six-vulnerability exploit chain that was publicly leaked through the ghh-jbDarkSword GitHub repository. It employs browser-based code to transition from a victim’s website visit to deeper device access, following a threat model similar to previous attacks against high-value iPhone users. The infrastructure includes fake AWS console pages, Apple ID credential-harvesting pages, and other disposable lure fronts. Notably, a server in Hong Kong hosted both an Apple-themed sign-in decoy and DarkSword staging content, combining credential theft and exploit delivery on the same system.

To evade detection, the operators expose several control panels on uncommon ports, such as 3000, 8443, and 8888. Some servers have hosted both DarkSword and Coruna, an older iOS exploit framework, indicating a possible connection between the two campaigns.

When a victim accesses a malicious page, they are served a staging page that silently loads a hidden frame and selects exploit code based on the iOS version. If successful, GHOSTBLADE components collect credentials, cloud data, saved Wi-Fi passwords, and files before transmitting the data to attacker-controlled endpoints. The operators also attempt to erase signs of compromise by deleting crash reports and logs before exiting. The use of Apple ID decoys is particularly concerning, as it allows for direct credential capture, mirroring tactics seen in previous Apple ID phishing campaigns.

For defenders, the report recommends monitoring stable page-body hashes and the full five-port Decode Dashboard pattern instead of relying solely on domain or IP blocklists. Security teams should conduct DarkSword exposure searches at least weekly due to the rapid rotation of hosts and web properties. iPhone users are strongly advised to install the latest iOS updates promptly. If immediate updates are not feasible, enabling Lockdown Mode can provide additional protection against targeted browser-based attacks. Users should also exercise caution with unexpected sign-in pages and unsolicited links, treating them as potential threats.

The rapid expansion and sophistication of the DarkSword exploit kit underscore the evolving nature of cyber threats targeting iOS devices. This development highlights the importance of proactive security measures, regular software updates, and user vigilance to mitigate the risks associated with such advanced exploit campaigns.