BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Chinese Hackers Use Leaked DarkSword Kit to Target iOS

Chinese hackers target iOS with DarkSword exploit, stealing crypto via fake AWS pages.

  • An unknown Chinese threat actor is targeting iOS devices using a publicly leaked version of the DarkSword exploit kit.
  • Over 100 malicious web properties, mostly fake AWS sign-in pages, have been identified by Censys, with hosting concentrated in Hong Kong but extending to Japan, the U.S., and Europe.
  • The exploit chain delivers GHOSTBLADE malware, stealing keychain, iCloud, and Wi-Fi credentials—data that could compromise cryptocurrency wallets stored on devices.
  • The attacker’s control panel reveals a Telegram contact and a group name “Asia-Pacific Group,” marking the first direct contact channel recovered.

An unknown Chinese threat actor has been running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit, according to an analysis by Censys published on July 31, 2026. The attack surface management platform identified the actor operating more than 100 web properties, most of which are fake Amazon Web Services sign-in pages hosted on a domain that also runs the exploit toolkit.

- Advertisement -

Censys researcher Aidan Holland noted that “the hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe.” DarkSword, previously detailed by Google Threat Intelligence Group, iVerify, and Lookout, is a full-chain exploit kit targeting iOS versions 18.4 through 18.7, used since at least November 2025.

The kit employs watering holes to trigger now-patched vulnerabilities, executing JavaScript that deploys the GHOSTBLADE information-stealing malware. On successful exploitation, the implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules, then exfiltrates the data to attacker-controlled endpoints—posing a direct risk to cryptocurrency holdings stored on compromised devices.

The attack flow begins when a victim reaches an AWS-console impersonation subdomain or Apple ID sign-in page, causing a malicious iframe to load the DarkSword chain. The attacker then logs in to one of three panels—DarkSword Admin, Decode Dashboard, or C2 Control Panel—to extract the pilfered data.

Censys found that the leaked source code, now publicly available on GitHub, has prompted other threat actors to join the exploitation bandwagon. The Singaporean host also runs an administration panel for Coruna, an older iOS exploit kit, with evidence linking a threat actor known as UNC6353 to both kits in attacks against Ukrainian targets.

- Advertisement -

The C2 Control Panel login page features a distinct design with a near-black background, red accent, animated particle effect, and a visible group name 亚太集团 (“Asia-Pacific Group”) along with a Telegram contact link. Holland stated, “That’s the first direct contact channel we’ve recovered for this operator; the other panels give us a login gate and nothing else.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AMD Q2 earnings: 48% revenue jump predicted after stellar growth

Analysts expect AMD to report Q2 revenue of $11.34 billion, a 48% year-over-year increase,...

Coldcard Hack Sparks Bitcoin Rush, $114M Stolen in 4th Wave

Transfers of less than 1 BTC reached 39,600 BTC on July 31, the highest...

Bitget to Exit Japan, Close Remaining Positions After Dec 31

Bitget has stopped accepting new registrations from residents of Japan as part of its...

FaceHugger flaws in Hugging Face Diffusers allow AI supply chain attacks

Three high-severity vulnerabilities, collectively named FaceHugger, were disclosed in Hugging Face's Diffusers library, allowing...

Bezos, Nvidia Join Forces to Fix Chip Materials Shortage

Bezos Expeditions backed CuspAI in a $450 million Series B round, pushing the Cambridge-based...

Must Read

8 Best Bitcoin Offshore Hosting Providers

In this blog post, we'll list the top 8 best bitcoin offshore hosting providers that accept Bitcoin and other cryptocurrencies.As Bitcoin continues to grow...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading