Leaked DarkSword kit exploited to target iOS
🛡️ Censys has identified a campaign run by an unknown Chinese-linked actor using a leaked version of the DarkSword exploit kit to target Apple iOS devices. The actor operated over 100 web properties, many impersonating AWS sign‑in pages, to host the toolkit and lure victims into watering‑hole attacks. Successful exploitation of iOS 18.4–18.7 triggers the DarkSword chain and deploys GHOSTBLADE modules to exfiltrate credentials and files. The infrastructure spans Hong Kong, Singapore, Japan, the US, Europe, and includes multiple admin panels and exposed tooling.
