BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Hackers Use Leaked DarkSword Kit to Target iOS

Chinese hackers target iOS with DarkSword exploit, stealing crypto via fake AWS pages.

  • An unknown Chinese threat actor is targeting iOS devices using a publicly leaked version of the DarkSword exploit kit.
  • Over 100 malicious web properties, mostly fake AWS sign-in pages, have been identified by Censys, with hosting concentrated in Hong Kong but extending to Japan, the U.S., and Europe.
  • The exploit chain delivers GHOSTBLADE malware, stealing keychain, iCloud, and Wi-Fi credentials—data that could compromise cryptocurrency wallets stored on devices.
  • The attacker’s control panel reveals a Telegram contact and a group name “Asia-Pacific Group,” marking the first direct contact channel recovered.

An unknown Chinese threat actor has been running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit, according to an analysis by Censys published on July 31, 2026. The attack surface management platform identified the actor operating more than 100 web properties, most of which are fake Amazon Web Services sign-in pages hosted on a domain that also runs the exploit toolkit.

- Advertisement -

Censys researcher Aidan Holland noted that “the hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe.” DarkSword, previously detailed by Google Threat Intelligence Group, iVerify, and Lookout, is a full-chain exploit kit targeting iOS versions 18.4 through 18.7, used since at least November 2025.

The kit employs watering holes to trigger now-patched vulnerabilities, executing JavaScript that deploys the GHOSTBLADE information-stealing malware. On successful exploitation, the implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules, then exfiltrates the data to attacker-controlled endpoints—posing a direct risk to cryptocurrency holdings stored on compromised devices.

The attack flow begins when a victim reaches an AWS-console impersonation subdomain or Apple ID sign-in page, causing a malicious iframe to load the DarkSword chain. The attacker then logs in to one of three panels—DarkSword Admin, Decode Dashboard, or C2 Control Panel—to extract the pilfered data.

Censys found that the leaked source code, now publicly available on GitHub, has prompted other threat actors to join the exploitation bandwagon. The Singaporean host also runs an administration panel for Coruna, an older iOS exploit kit, with evidence linking a threat actor known as UNC6353 to both kits in attacks against Ukrainian targets.

- Advertisement -

The C2 Control Panel login page features a distinct design with a near-black background, red accent, animated particle effect, and a visible group name 亚太集团 (“Asia-Pacific Group”) along with a Telegram contact link. Holland stated, “That’s the first direct contact channel we’ve recovered for this operator; the other panels give us a login gate and nothing else.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BitMine Chairman Touts Largest Crypto Treasury Buyback

BitMine Immersion Technologies purchased 15,112 ETH last week, its smallest weekly buy since mid-August,...

Hiero SDK adds native MirrorNodeAccountBalanceQuery for HBAR

Hedera has introduced MirrorNodeAccountBalanceQuery in the JavaScript, Java, and Go Hiero SDKs as a...

Live Nation doubles CEO pay to $60M despite monopoly verdict

Live Nation approved a contract doubling CEO Michael Rapino’s annual compensation target to over...

Metaplanet adopts net interest strategy to fuel Bitcoin

Metaplanet is adopting a net interest income strategy, keeping Bitcoin as 85%-90% of total...

Cling botnet exploits Realtek flaw via STUN C2

Threat actors are exploiting a critical Realtek SDK flaw (CVE-2021-35394) to deploy a new...

Must Read

7 Best Audiobooks on Cybersecurity

Cybersecurity has become an essential topic in our increasingly digital world. As technology evolves and becomes more integrated into our daily lives, the importance...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading