A Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. According to attack surface management platform Censys, the actor operates more than 100 web properties, mostly fake Amazon Web Services (AWS) sign-in pages, on a domain that also hosts the exploit toolkit. The hosting is concentrated in Hong Kong but extends to Japan, the United States, and Europe.
DarkSword, first detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, is a full-chain exploit kit believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025. The kit targets iOS versions 18.4 through 18.7 and uses watering holes to trigger now-patched vulnerabilities, executing JavaScript that ultimately deploys GHOSTBLADE, an information-stealing malware.
The latest findings from Censys show that the login page for a panel called “DarkSword Admin” matches seven hosts across three countries as of July 30, 2026. One login panel contains Chinese-language field labels. The attack flow begins when a victim reaches an AWS-console impersonation subdomain or an Apple ID sign-in page, causing a malicious iframe to load JavaScript that fires the DarkSword chain and deploys GHOSTBLADE modules. The implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules and commences file-exfiltration. Harvested data is packaged and transmitted to attacker-controlled endpoints.
The attacker then logs into one of the panels—DarkSword Admin, Decode Dashboard, or C2 Control Panel—to extract the pilfered data. Censys noted that the cluster runs the leaked kit rather than a reimplementation, evidenced by a shared staging-page hash and Russian-language code comments carried over from the leaked source. Additionally, a Singaporean host was found to host an administration panel for Coruna, another iOS exploit kit predating DarkSword. There is evidence suggesting that threat actor UNC6353 has leveraged both exploit kits in attacks aimed at Ukrainian targets.
Censys also discovered an open directory listing in Frankfurt exposing the operator’s tooling, including an SSH key comment “jkcing@apt,” a web-content fuzzer, and references to a previously undocumented malware family referred to as Thorn C2. The C2 Control Panel login features a distinct visual design with a near-black background, red accent, an animated particle-canvas effect, a group name rendered directly on the page (亚太集团, ‘Asia-Pacific Group’), and a visible Telegram contact link. This is the first direct contact channel recovered for this operator.
CVEs: CVE-2026-50522
Attack groups: UNC6353
Malware: GHOSTBLADE, DarkSword, Coruna, Thorn C2
Companies: Censys, Google Threat Intelligence Group, iVerify, Lookout
Original source: thehackernews.com