BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Hackers Use Leaked DarkSword Kit to Target iOS

Chinese hackers target iOS with DarkSword exploit, stealing crypto via fake AWS pages.

  • An unknown Chinese threat actor is targeting iOS devices using a publicly leaked version of the DarkSword exploit kit.
  • Over 100 malicious web properties, mostly fake AWS sign-in pages, have been identified by Censys, with hosting concentrated in Hong Kong but extending to Japan, the U.S., and Europe.
  • The exploit chain delivers GHOSTBLADE malware, stealing keychain, iCloud, and Wi-Fi credentials—data that could compromise cryptocurrency wallets stored on devices.
  • The attacker’s control panel reveals a Telegram contact and a group name “Asia-Pacific Group,” marking the first direct contact channel recovered.

An unknown Chinese threat actor has been running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit, according to an analysis by Censys published on July 31, 2026. The attack surface management platform identified the actor operating more than 100 web properties, most of which are fake Amazon Web Services sign-in pages hosted on a domain that also runs the exploit toolkit.

- Advertisement -

Censys researcher Aidan Holland noted that “the hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe.” DarkSword, previously detailed by Google Threat Intelligence Group, iVerify, and Lookout, is a full-chain exploit kit targeting iOS versions 18.4 through 18.7, used since at least November 2025.

The kit employs watering holes to trigger now-patched vulnerabilities, executing JavaScript that deploys the GHOSTBLADE information-stealing malware. On successful exploitation, the implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules, then exfiltrates the data to attacker-controlled endpoints—posing a direct risk to cryptocurrency holdings stored on compromised devices.

The attack flow begins when a victim reaches an AWS-console impersonation subdomain or Apple ID sign-in page, causing a malicious iframe to load the DarkSword chain. The attacker then logs in to one of three panels—DarkSword Admin, Decode Dashboard, or C2 Control Panel—to extract the pilfered data.

Censys found that the leaked source code, now publicly available on GitHub, has prompted other threat actors to join the exploitation bandwagon. The Singaporean host also runs an administration panel for Coruna, an older iOS exploit kit, with evidence linking a threat actor known as UNC6353 to both kits in attacks against Ukrainian targets.

- Advertisement -

The C2 Control Panel login page features a distinct design with a near-black background, red accent, animated particle effect, and a visible group name 亚太集团 (“Asia-Pacific Group”) along with a Telegram contact link. Holland stated, “That’s the first direct contact channel we’ve recovered for this operator; the other panels give us a login gate and nothing else.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

CLARITY Act odds crash as Democrats reject ethics offer

Polymarket odds for the CLARITY Act plunged to 16% on Monday after key Senate...

Oracle Layoffs: India Faces New Job Cuts As AI Spending Grows

Oracle cut thousands of US jobs on September 14, 2026, but has not confirmed...

Robinhood adds share voting rights to stock tokens amid criticism

Robinhood CEO Vlad Tenev announced plans to introduce in-kind redemption and voting rights for...

Democrats plan counterproposal to GOP’s final crypto bill offer

Senate Democrats are preparing a counterproposal to the GOP's final revised CLARITY Act text.Republicans...

8 banking groups urge Senate to tighten stablecoin rewards

Eight banking trade groups urged Senate leaders to tighten restrictions on stablecoin rewardsThe groups...

Must Read

The 13 Best Crypto Advertising Networks to Grow Your Project

TABLE OF CONTENTSWhy Traditional Ad Networks (Like Google & Facebook) Fail CryptoQuick-View Comparison TableHow to Choose the Right Crypto Ad Network for Your ProjectBest...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading