The Hacker News31%
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS 39%
By Ravie Lakshmanan21%
8/3/2026, 3:49:00 AM
Keywords: Darksword, Ghostblade, Ios, Exploit Kit, Malware, Threat Actor, Credential Theft, Phishing, Watering Hole
BS Summary: This article contains 18 faulty reasoning types, including Appeal to Authority, Ambiguity (Equivocation), and Biased Writer Voice, with Overconfidence Bias as the most egregious example at 19.7% saturation with 129 hits. Analysis detected 1,240 faulty-reasoning hits from 656 analyzed words, generating a BS Score of 37.6% and a BS Rank of 39% (17,950 of 29,322 articles). This article is better (less manipulative) than 61.20% of the article peer group.
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.
Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit.
"The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe," Censys researcher Aidan Holland said in an analysis published on July 31, 2026.
DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.
The kit, which specifically targets iOS versions 18.4 through 18.7, has been observed to employ watering holes as a starting point to trigger now-patched vulnerabilities in Apple's mobile operating system to execute JavaScript that ultimately facilitates the deployment of GHOSTBLADE, an information-stealing malware.
The use of DarkSword has since expanded in scope following a public leak of its source code, prompting other threat actors to join the exploitation bandwagon.
The latest findings from Censys show that the login page for a panel called "DarkSword Admin" matches seven hosts across three countries as of July 30, 2026, in addition to a Singapore-based host ("38.181.52[.]95") running three distinct exploit-panel front ends and a Hong Kong host that bundles an Apple ID credential-harvesting decoy ("103.106.190[.]
217").
One such login panel served on the IP address "38.22.89[.]117:8888" contains Chinese-language field labels for "username," "password," and "Log in."
The other six IP addresses are below -
103.97.128[.]
67:8888
162.4.136[.]
30:8888
223.26.63[.]
56:8888
151.243.126[.]
191:8888
107.175.49[.]
181:3000
103.238.129[.]
112:3000
The attack flow is fairly consistent in that it begins when a victim reaches one of the operator's domains - an AWS-console impersonation subdomain or an Apple ID sign-in page - causing a malicious iframe element to load JavaScript that fires the DarkSword chain and finally deploys GHOSTBLADE modules.
On successful exploitation, the implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules and commences the file-exfiltration sweep.
The harvested data is then packaged and transmitted to attacker-controlled endpoints.
The attacker then logs in to one of the panels, namely DarkSword Admin, Decode Dashboard, or C2 Control Panel, to extract the pilfered data.
The IP addresses associated with the two other login panels are as follows -
103.226.155[.]
200 (Decode Dashboard)
103.226.155[.]
201 (Decode Dashboard)
202.8.120[.]
249 (Decode Dashboard)
103.106.190[.]
217 (C2 Control Panel), which also co-hosts the Apple ID decoy sign-in page
"This cluster runs the leaked kit rather than a reimplementation, and the evidence is a shared staging-page hash plus Russian-language code comments carried over from the leaked source," Holland said.
What's more, the Singaporean host (now no longer active) has been found to host an administration panel for Coruna, another iOS exploit kit that predates DarkSword and goes after iOS versions 3.0 through 17.2.1.
There is some evidence to suggest that a threat actor known as UNC6353 has leveraged both exploit kits in its attacks aimed at Ukrainian targets.
Censys said it also discovered an open directory listing in Frankfurt ("93.152.221[.]37") that exposes the operator's tooling, including an SSH key comment "jkcing@apt," a web-content fuzzer, and references to a previously undocumented malware family referred to as Thorn C2.
"The 'C2 Control Panel' login itself is a visually distinct build from the other two panels: a near-black #06060d background, a #ff0050 red accent, an animated particle-canvas effect, a group name rendered directly on the page (亚太集团, 'Asia-Pacific Group'), and a visible Telegram contact link, hxxps://t[.]me/YATA0000," it noted.
"That's the first direct contact channel we've recovered for this operator; the other panels give us a login gate and nothing else."
Speakers
1speaker8.8%attributed speech598writer words
Selected voice
100%flagged-word coverageAidan Holland
58 attributed words100% of attributed speech90% writer coverage
Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.
Loading…
Loading…
Loading…
Loading…
Analysis
Hover over highlighted words in the article to view the associated bias or fallacy analysis.