DarkSword, the iOS Exploit Kit Code Is Public: A Campaign with 100 Lure Sites Targets Those Who Don’t Update
The leaked DarkSword iOS exploit kit code fuels a campaign using 100+ AWS and Apple ID lure sites to deliver GHOSTBLADE malware and steal user credentials.
Illustrative image generated with AI
Leaked Code Becomes a Weapon for an Unknown Actor
The full-chain iOS exploit kit known as DarkSword was first documented by Google Threat Intelligence Group, iVerify, and Lookout in late 2025. Since then, several commercial surveillance vendors and state-sponsored actors have used it against iOS versions between 18.4 and 18.7. The new development is that the original source code—identifiable by the staging component hash and Russian-language comments—is now in the hands of an as-yet-unidentified Chinese-speaking threat group.
This is not a reimplementation: technical analysis confirms the actor is using the leaked code as-is, with minimal customization. This lowers the barrier to entry and makes the operation scalable for anyone who gets hold of the source.
Over One Hundred Domains: AWS and Apple ID as Lures
The campaign uses more than 100 web properties, overwhelmingly counterfeit login pages for AWS services, hosted primarily on infrastructure in Hong Kong with branches in Japan, the United States, and Europe. Some pages also mimic Apple ID login.
The infection mechanism is straightforward: the victim visits one of these lure sites and loads, often unknowingly, a malicious iframe. The JavaScript in the DarkSword kit attempts to exploit iOS vulnerabilities—all subsequently patched by Apple—and, if the device is not updated, delivers the GHOSTBLADE malware.
GHOSTBLADE: Drains the Keychain and Exfiltrates Files
Once executed on the device, GHOSTBLADE systematically dumps credentials. It steals iOS keychain items, iCloud access tokens, and stored Wi‑Fi passwords. At the same time, it exfiltrates local files and transfers everything to attacker‑controlled endpoints.
The impact is twofold: direct identity theft and compromise of business and personal cloud accounts. Stolen data feeds an ecosystem that, as infrastructure details suggest, includes resale or dedicated support channels.
Chinese‑Language Control Panels, a Telegram Contact, and the Shadow of Coruna
Censys identified several management panels exposed on public IP addresses. The names are telling: “DarkSword Admin,” “Decode Dashboard,” “C2 Control Panel.” The interface labels are written in Chinese. The C2 panel displays the text “Asia‑Pacific Group” (亚太集团) and a Telegram contact (hxxps://t[.]me/YATA0000), hinting at an operation offering support or selling access.
A Singapore‑based host, now unreachable, exposed the administration panel for Coruna, another iOS exploit kit for versions 3.0–17.2.1, previously attributed to UNC6353, known for targeting Ukrainian entities. Infrastructure sharing or tool handoffs between different actors remains an open question.
A public directory on a Frankfurt server (93.152.221[.]37) rounds out the picture: it contained operator tools, including a web fuzzer, references to Thorn C2 malware, and an SSH key with the comment “jkcing@apt.” The “APT” in the comment, together with the rest of the infrastructure, reinforces the profile of a persistent, organized actor.
What to Do: Update, Block, Verify
The vulnerabilities exploited by DarkSword have been patched by Apple. The most effective protection remains keeping iOS up to date. For network security teams, it’s advisable to block traffic to the indicators of compromise already identified, including:
- 103.97.128[.]67:8888
- 162.4.136[.]30:8888
- 223.26.63[.]56:8888
- 151.243.126[.]191:8888
- 107.175.49[.]181:3000
- 103.238.129[.]112:3000
- 38.22.89[.]117:8888
- 103.226.155[.]200
- 103.226.155[.]201
- 202.8.120[.]249
- 103.106.190[.]217
For end users, a simple rule applies: never enter credentials on login pages reached via links from email, SMS, or sites you do not fully trust, even when the interface looks identical to the legitimate one.
Sources
This article is an original reworking based on the sources below.




