- An unknown Chinese threat actor is targeting iOS devices using a publicly leaked version of the DarkSword exploit kit.
- Over 100 malicious web properties, mostly fake AWS sign-in pages, have been identified by Censys, with hosting concentrated in Hong Kong but extending to Japan, the U.S., and Europe.
- The exploit chain delivers GHOSTBLADE malware, stealing keychain, iCloud, and Wi-Fi credentials—data that could compromise cryptocurrency wallets stored on devices.
- The attacker’s control panel reveals a Telegram contact and a group name “Asia-Pacific Group,” marking the first direct contact channel recovered.
An unknown Chinese threat actor has been running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit, according to an analysis by Censys published on July 31, 2026. The attack surface management platform identified the actor operating more than 100 web properties, most of which are fake Amazon Web Services sign-in pages hosted on a domain that also runs the exploit toolkit.
Censys researcher Aidan Holland noted that “the hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe.” DarkSword, previously detailed by Google Threat Intelligence Group, iVerify, and Lookout, is a full-chain exploit kit targeting iOS versions 18.4 through 18.7, used since at least November 2025.
The kit employs watering holes to trigger now-patched vulnerabilities, executing JavaScript that deploys the GHOSTBLADE information-stealing malware. On successful exploitation, the implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules, then exfiltrates the data to attacker-controlled endpoints—posing a direct risk to cryptocurrency holdings stored on compromised devices.
The attack flow begins when a victim reaches an AWS-console impersonation subdomain or Apple ID sign-in page, causing a malicious iframe to load the DarkSword chain. The attacker then logs in to one of three panels—DarkSword Admin, Decode Dashboard, or C2 Control Panel—to extract the pilfered data.
Censys found that the leaked source code, now publicly available on GitHub, has prompted other threat actors to join the exploitation bandwagon. The Singaporean host also runs an administration panel for Coruna, an older iOS exploit kit, with evidence linking a threat actor known as UNC6353 to both kits in attacks against Ukrainian targets.
The C2 Control Panel login page features a distinct design with a near-black background, red accent, animated particle effect, and a visible group name 亚太集团 (“Asia-Pacific Group”) along with a Telegram contact link. Holland stated, “That’s the first direct contact channel we’ve recovered for this operator; the other panels give us a login gate and nothing else.”
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
Previous Articles:
- AMD Q2 earnings: 48% revenue jump predicted after stellar growth
- Coldcard Hack Sparks Bitcoin Rush, $114M Stolen in 4th Wave
- Bitget to Exit Japan, Close Remaining Positions After Dec 31
- FaceHugger flaws in Hugging Face Diffusers allow AI supply chain attacks
- Bezos, Nvidia Join Forces to Fix Chip Materials Shortage
