The DarkSword operator attack flow | Image: Censys
At a glance
| Actor | Chinese-speaking operator (suspected, moderate confidence); one of 7-8 unrelated groups using the leaked kit |
| Activity | iOS exploit-kit operation, credential harvesting, spyware-style data theft |
| Targets | iPhone and iPad users on iOS 18.4 through 18.7 |
| Scale | 100+ web properties; kit in the hands of at least seven, probably eight, operators |
| Law-enforcement status | No arrests or charges announced; infrastructure investigation |
| Source | Censys (Aidan Holland) |
TL;DR
A leaked iOS exploit kit called DarkSword has spread far beyond its first users. Censys now tracks a Chinese-speaking operator running the DarkSword iOS exploit across more than 100 web properties. The chain drops the GHOSTBLADE implant, which steals keychain, iCloud, and Wi-Fi data.
What happened
DarkSword began as a commercial iOS exploit chain. Google, iVerify, and Lookout documented it in March 2026. Then someone leaked the full kit on GitHub. As Censys puts it, DarkSword is “six chained vulnerabilities spanning iOS 18.4 through 18.7.” That leak lowered the bar for entry.
Now the kit runs in the hands of “at least seven, and probably eight, unrelated operators.” Censys re-scanned the live infrastructure of the newest one. It found more than 100 web properties, many fronted by fake AWS or Apple sign-in pages. “The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe,” the report says. Notably, the team needed no malware sample. “None of this required source access or a sample in hand,” they wrote.
How the attack works
The flow is consistent. A victim visits a lure domain, often a fake AWS or Apple ID page. The site serves an identical staging page, no matter the domain. A hidden iframe then loads the six-vulnerability DarkSword iOS exploit. On success, the implant drops GHOSTBLADE modules. These dump keychain, iCloud, and Wi-Fi credentials, then sweep files. The stolen data flows to a collector endpoint. Finally, the implant deletes crash logs and exits. Operators review the loot through login panels named “DarkSword Admin,” “Decode Dashboard,” or “C2 Control Panel.”
One tracking trick stands out
Domains in this cluster are disposable. The operator panels are not. So Censys pivoted on a single login-page body hash to map the spread. That hash matched seven hosts across three countries, even as individual hosts churned every few days. Ports change too. As the report notes, “the port is a free choice, not a constraint.” A body hash therefore beats a port or domain rule for defenders.
Censys also hashed the kit’s files across 100 sites. The payload modules stayed identical everywhere. Only the version-dispatch code varied, since it must match each iOS build. That split points to one shared codebase, not a crowd of copycats.
Who is behind it
Attribution here needs care. Censys assesses the new cluster, at moderate confidence, as a Chinese-speaking operator. Chinese-language panel titles, zh-CN markup, and a group name meaning “Asia-Pacific Group” support that read. The researchers also recovered a Telegram contact channel and an SSH key comment as leads. Both remain unverified. Importantly, Censys does not tie this operator to UNC6353. That is the group Google linked to DarkSword’s original, targeted use against Ukraine. Because the leaked kit now serves many hands, shared code does not prove a shared operator.
One now-defunct Singapore host raised the stakes further. It ran DarkSword and Coruna panels side by side. Coruna is an older iOS kit tied to earlier espionage campaigns. Running two exploit families on one box was new for this leaked-kit lineage.
A new and worrying twist
For the first time in this cluster, one host bundled an Apple ID phishing page directly onto exploit staging. Earlier lures copied AWS or Chinese web services. This one mimics an iCloud sign-in. As Censys warns, “A chain that already exfiltrates the iOS keychain and iCloud data is one step from just asking the victim for their Apple ID password directly.”
Impact and scale
The numbers keep moving. The Censys label spanned 27 hosts and 180 web properties on 30 July. A separate April scan hashed files from 100 web properties. Most hosts live days, not weeks. Reporting elsewhere ties DarkSword’s earlier use to campaigns across Saudi Arabia, Turkey, Malaysia, and Ukraine since late 2025. No arrests or charges have been announced so far.
How to stay protected
The fix is clear. Update iPhones and iPads to iOS 26, which closes the full chain. Apple also shipped an emergency patch in March for older devices. Turning on Lockdown Mode blocks these attacks, even on outdated software. Avoid signing into Apple or AWS pages reached through ads, forums, or messages. Defenders should hunt on the panel body hash rather than ports or domains.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.