DarkSword , the notorious iOS exploit kit , is at the center of a new cyberattack by an unknown Chinese threat actor that is exploiting the leak of its source code. Censys has identified an infrastructure of over 100 web properties , primarily fake Amazon Web Services (AWS) login pages , used to deliver the GHOSTBLADE malware to Apple devices running vulnerable versions of iOS . The attack is a prime example of the “post-leak weaponization” of a sophisticated cyberespionage tool.
See also: Hackers say they breached CrowdStrike's Threat Actor Database

DarkSword was discovered and analyzed earlier this year by the Google Threat Intelligence Group (GTIG) , iVerify , and Lookout . It is a full-chain exploit kit believed to have been used by commercial surveillance software vendors and state-backed actors in campaigns targeting Saudi Arabia , Turkey , Malaysia , and Ukraine since at least November 2025. The kit specifically targets iOS versions 18.4 through 18.7 and uses watering hole techniques to exploit vulnerabilities in Apple ’s operating system .
The significance of the current campaign lies in the fact that the DarkSword source code was leaked publicly on GitHub , dramatically lowering the barrier to entry for additional threat actors. What was once a tool exclusively for top state-run groups has become accessible to a wider circle of attackers — a development that researchers describe as the “democratization” of iPhone exploitation.
DarkSword: Technical analysis of the exploit kit and the attack chain
DarkSword is a highly sophisticated browser- to -kernel exploit kit that chains six vulnerabilities at different levels of the operating system. The exploit chain starts with WebKit 's JavaScriptCore JIT , progresses to PAC bypass, sandbox escape , and ends with a kernel-level compromise . The result is a complete compromise of the device through a simple visit to a website, without requiring application installation or user interaction beyond clicking on the link.
Censys researcher Aidan Holland described in his analysis (July 31 , 2026) that the threat actor's infrastructure is centered in Hong Kong but extends to Japan , the US , and Europe . A login table at IP address 38.22.89[.]117:8888 contains field labels in Chinese for "username," "password," and "login," revealing the origin of the operator. The attack flow begins when a victim visits one of the operator's domains — either a fake AWS console page or an Apple ID login page — causing a malicious iframe to load that executes JavaScript and triggers the DarkSword chain .
After successful exploitation, the implant delivers modules to extract data from keychain , iCloud , and Wi-Fi credentials , and initiates a full file scan. The collected data is packaged and transmitted to endpoints under the attacker’s control. The operator then logs into one of the dashboards — DarkSword Admin , Decode Dashboard , or C2 Control Panel — to extract the stolen data.
See also: Apple: Old iPhones vulnerable to Coruna and DarkSword exploits

DarkSword and GHOSTBLADE: The iOS Malware Ecosystem
GHOSTBLADE is the main payload delivered via DarkSword and is a sophisticated information-stealing malware . It targets sensitive data such as the device keychain , iCloud credentials , Wi-Fi passwords, browsing history, messages, photos, notes, emails, location data, and cryptocurrency wallet hardware . The kit is also related to other malware families such as GHOSTKNIFE and GHOSTSABER , suggesting a broader ecosystem of spyware tools.
Censys also discovered an open directory listing in Frankfurt (IP: 93.152.221[.]37 ) that exposes the operator’s tools, including an SSH key comment “jkcing@apt,” a web-content fuzzer , and references to a previously undeclared malware family called Thorn C2 . The “C2 Control Panel” panel displays characteristic elements: dark background #06060d , red highlighting #ff0050 , animated particle-canvas effect , the group name亚太集团 (“Asia-Pacific Group”) , and a visible Telegram contact link — the first direct contact channel recovered for this operator.
It is worth noting that a Singaporean node (now inactive) hosted a control panel for Coruna, another iOS that predates DarkSword and targets iOS versions 3.0 through 17.2.1. There is evidence that threat actor UNC6353 has used both exploit kits in attacks against Ukrainian targets, revealing a broader ecosystem of tool sharing between state-backed groups.
iVerify estimated that, assuming all iOS 18 versions were vulnerable throughout most of the chain, approximately 17.3% of users or 270 million devices could be affected. Apple responded by expanding the availability of iOS 18.7.7 / iPadOS 18.7.7 to protect more devices from DarkSword -related attacks , thereby recognizing the severity of the threat.
How to protect yourself from DarkSword and similar iOS attacks
The first and most critical action is to immediately update all iPhone and iPad devices to the latest version of iOS/iPadOS . Devices running iOS 18.4 through 18.7 are particularly vulnerable and should be updated immediately. Enabling Automatic Updates ensures that security fixes are applied quickly, without requiring manual intervention.
For high-risk users — business executives, journalists, activists, and security personnel — enabling Lockdown Mode, as DarkSword is a browser-delivered attack that targets web attack surfaces. Additionally, avoiding clicking on suspicious links, particularly on pages that mimic cloud services like AWS or Apple ID, is an essential precaution. Organizations should also monitor for unusual access to iCloud, keychain , or Wi-Fi, as these are the primary assets targeted by GHOSTBLADE after successful exploitation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: DarkSword: Apple to release rare iOS 18 software update

Overall, the DarkSword highlights a worrying trend: the release of sophisticated exploit kits into the public domain is not just an academic issue, but has direct and measurable consequences for millions of users worldwide. The cybersecurity community is faced with a world where tools that were once the exclusive preserve of government agencies are becoming increasingly accessible — with a correspondingly increased risk to end users.
