Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Overcast Clouds Humidity: 89%
Wind: 1.03 M/S

Chinese APT Exploits DarkSword Toolkit to Spread GHOSTBLADE Across iOS Devices

Chinese APT Exploits DarkSword Toolkit to Spread GHOSTBLADE Across iOS Devices

A previously unidentified Chinese-speaking threat actor has been linked to an extensive campaign targeting Apple iPhone users through the use of a publicly leaked version of the DarkSword exploit framework, a sophisticated iOS attack toolkit originally associated with commercial spyware operators and suspected state-sponsored surveillance activity.

According to researchers at attack surface management firm Censys, the threat actor operates more than 100 malicious web properties, many of which impersonate Amazon Web Services (AWS) login portals while secretly hosting DarkSword exploitation infrastructure. The campaign's infrastructure is primarily concentrated in Hong Kong, although servers and supporting systems have also been identified in Japan, the United States, Europe, and other regions. 

DarkSword's Growing Threat Landscape

DarkSword first came to public attention earlier in 2026 following investigations by multiple security companies. The framework is a full-chain iOS exploitation platform capable of targeting vulnerable Apple devices running iOS versions 18.4 through 18.7.

The toolkit was previously tied to operations targeting individuals in countries including:

  • Saudi Arabia
  • Turkey
  • Malaysia
  • Ukraine

Security researchers believe it was actively used as early as late 2025 by surveillance operators and advanced threat actors seeking to compromise iOS devices. Once triggered, the framework exploits vulnerabilities in iOS to deploy GHOSTBLADE, a sophisticated malware family designed to steal sensitive user data.

The threat landscape expanded significantly after DarkSword's source code was leaked publicly, enabling additional threat actors to adopt and deploy the toolkit in their own campaigns.

Extensive Infrastructure Identified Across Multiple Countries

Censys researchers discovered several active administrative panels associated with the campaign.

Investigators identified multiple instances of a web interface known as DarkSword Admin, which appeared across servers hosted in several countries. One administration portal contained Chinese-language authentication fields for:

  • Username
  • Password
  • Login

The discovery of multiple management consoles suggests the threat actor maintains a distributed operational infrastructure capable of managing large-scale exploitation activities.

Researchers also identified additional supporting systems, including:

  • Decode Dashboard servers
  • Command-and-Control (C2) management panels
  • Credential harvesting portals
  • Exploit delivery infrastructure

One Hong Kong-based system simultaneously hosted exploit infrastructure and a fraudulent Apple ID login page designed to harvest user credentials.

Attack Chain Begins With Fake Login Pages

The attack process generally follows a consistent pattern.

Victims are lured to websites impersonating legitimate services, including:

  • AWS Console login portals
  • Apple ID authentication pages

When a victim visits one of these fraudulent websites, malicious code embedded within the page activates an invisible iframe that loads exploit-related JavaScript.

The script launches the DarkSword exploit chain, ultimately leading to the installation of GHOSTBLADE malware on vulnerable iOS devices.

GHOSTBLADE Targets Sensitive User Data

Once exploitation succeeds, GHOSTBLADE begins collecting a wide range of sensitive information from the compromised device.

Researchers observed modules specifically designed to harvest:

  • Apple Keychain contents
  • iCloud-related credentials
  • Saved Wi-Fi passwords
  • Device configuration data
  • User files and stored information

The malware then packages the stolen data and transmits it back to attacker-controlled infrastructure for collection and analysis.

Threat operators subsequently access the information through dedicated administration panels, including:

  • DarkSword Admin
  • Decode Dashboard
  • C2 Control Panel

Evidence Indicates Use of the Original Leaked Toolkit

Researchers concluded that the threat actor is using the actual leaked DarkSword source code rather than a custom reimplementation.

Several factors support this assessment, including:

  • Matching staging-page fingerprints
  • Identical code structures
  • Russian-language comments preserved from the leaked source code
  • Shared deployment characteristics

These similarities strongly suggest the attackers adopted the original leaked toolkit with only minimal modifications.

Connections to Other iOS Exploit Frameworks

Investigators also uncovered evidence linking the campaign to another iOS exploitation platform known as Coruna, an earlier toolkit capable of targeting significantly older versions of Apple's operating system.

Coruna reportedly supported attacks against devices running iOS versions ranging from 3.0 through 17.2.1.

One now-inactive server based in Singapore was found hosting management infrastructure associated with both exploit frameworks, suggesting operational overlap between the toolsets.

Researchers noted similarities to activities previously attributed to a threat cluster tracked as UNC6353, which has targeted Ukrainian interests in the past.

Additional Malware and Operational Tools Exposed

The investigation revealed further insights after researchers discovered an exposed directory on a server located in Frankfurt.

The open directory contained various operational tools, including:

  • SSH-related resources
  • Web-content fuzzing utilities
  • Infrastructure management tools
  • References to a previously undocumented malware platform called Thorn C2

One notable artifact included an SSH key comment containing the string:

jkcing@apt

This finding may provide additional clues regarding the operators behind the campaign and their broader tooling ecosystem.

"Asia-Pacific Group" Branding Appears on Control Infrastructure

Researchers also highlighted differences between the command-and-control infrastructure and the more standard exploit administration panels.

The primary C2 portal featured:

  • A distinct dark-themed design
  • Red-accented user interface elements
  • Animated graphical effects
  • Chinese-language branding

Most notably, the interface displayed the name:

亚太集团 ("Asia-Pacific Group")

The portal also exposed a direct Telegram contact channel, providing investigators with the first publicly identified communication method associated with the operator.

Unlike the DarkSword and Decode Dashboard panels, which remain hidden behind authentication gateways, the C2 interface provided additional operational visibility into the group's infrastructure.

Growing Risk Following Public Exploit Leaks

The emergence of this campaign highlights an increasingly common trend in modern cyber operations: the rapid proliferation of advanced attack capabilities following public source-code leaks.

When sophisticated offensive frameworks become publicly available, they often transition from being exclusive tools used by highly skilled operators to widely adopted platforms leveraged by a broader range of threat actors.

In the case of DarkSword, researchers now see evidence that multiple groups may be exploiting the leaked codebase to target iOS users worldwide.

Conclusion

The newly discovered campaign demonstrates how leaked exploitation frameworks can significantly expand the cyber threat landscape. By weaponizing the leaked DarkSword toolkit, a Chinese-speaking threat actor has built an extensive infrastructure capable of compromising vulnerable iOS devices and deploying the GHOSTBLADE information-stealing malware.

With fake AWS and Apple ID pages serving as entry points, victims can unknowingly trigger a sophisticated exploit chain that harvests credentials, extracts sensitive data, and transmits the information to attacker-controlled systems. The findings also reveal growing links between multiple iOS exploit frameworks and highlight the continuing evolution of mobile-focused cyber-espionage operations.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.