A previously unidentified Chinese threat actor has been linked to a campaign targeting Apple iOS devices by using a publicly leaked version of the DarkSword exploit kit.
According to attack surface management company Censys, researchers uncovered more than 100 malicious web properties operated by the threat actor. Most of these sites impersonate Amazon Web Services (AWS) login pages and are hosted on infrastructure that also serves the exploit toolkit.
“The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe,” Censys researcher Aidan Holland said in an analysis published on July 31, 2026.
DarkSword, which was first documented earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, is a full-chain iOS exploit kit believed to have been used by commercial surveillance vendors and suspected state-sponsored actors. Previous campaigns have targeted organizations and individuals in Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.
The toolkit specifically targets iOS versions 18.4 through 18.7. It typically begins with watering-hole attacks that exploit now-patched Apple vulnerabilities, executing malicious JavaScript that ultimately installs GHOSTBLADE, an information-stealing malware.
Since the DarkSword source code was publicly leaked, its use has expanded beyond the original operators, allowing additional threat actors to adopt the toolkit for their own campaigns.
Censys’ latest investigation found that the “DarkSword Admin” login panel matched seven hosts across three countries as of July 30, 2026. Researchers also identified a Singapore-based host (“38.181.52[.]95”) running three separate exploit-panel interfaces and a Hong Kong-based server (“103.106.190[.]217”) hosting both the toolkit and an Apple ID credential-harvesting page.
One login panel hosted at IP address “38.22.89[.]117:8888” contains Chinese-language fields labeled “username,” “password,” and “Log in.” Researchers also identified several additional servers linked to the campaign across multiple regions, indicating a broader infrastructure supporting the operation:
- 103.97.128[.]67:8888
- 162.4.136[.]30:8888
- 223.26.63[.]56:8888
- 151.243.126[.]191:8888
- 107.175.49[.]181:3000
- 103.238.129[.]112:3000
The attack sequence remains consistent throughout the campaign. Victims first visit one of the attacker-controlled domains, either an AWS Console impersonation site or a fake Apple ID sign-in page. A malicious iframe then loads JavaScript that triggers the DarkSword exploit chain, eventually deploying GHOSTBLADE modules onto the compromised device.

Once exploitation succeeds, the malware activates modules designed to extract keychain data, iCloud credentials, and saved Wi-Fi information before beginning a broader file-exfiltration process. The collected information is packaged and transmitted to attacker-controlled servers. Operators later retrieve the stolen data through one of several management interfaces, including DarkSword Admin, Decode Dashboard, or the C2 Control Panel.
Researchers also identified additional infrastructure supporting the Decode Dashboard and C2 Control Panel, further indicating that multiple management interfaces were used throughout the campaign:
- 103.226.155[.]200 (Decode Dashboard)
- 103.226.155[.]201 (Decode Dashboard)
- 202.8.120[.]249 (Decode Dashboard)
- 103.106.190[.]217 (C2 Control Panel), which also hosts the Apple ID phishing page
According to Holland, the campaign appears to rely on the leaked DarkSword toolkit rather than a newly developed version. This conclusion is supported by a shared staging-page hash and Russian-language code comments that remain embedded in the leaked source code.
Researchers also discovered that the Singapore-based host, which is no longer active, previously hosted an administration panel for Coruna an older iOS exploit kit targeting devices running iOS versions 3.0 through 17.2.1. Available evidence suggests that the threat actor tracked as UNC6353 has previously used both Coruna and DarkSword in attacks targeting Ukrainian entities.
In addition, Censys identified an exposed directory listing on a Frankfurt-based server (“93.152.221[.]37”) that revealed operational tooling. The exposed resources included an SSH key comment labeled “jkcing@apt,” a web-content fuzzer, and references to a previously undocumented malware family named Thorn C2.
Researchers also highlighted that the “C2 Control Panel” differs visually from the other administration panels. It features a near-black (#06060d) background, a red (#ff0050) accent color, animated particle effects, the group name “亚太集团” (“Asia-Pacific Group”), and a visible Telegram contact link, hxxps://t[.]me/YATA0000. communication channel embedded within the interface.”
This is the first direct contact channel we’ve recovered for this operator,” Censys noted. “The other panels expose only login interfaces, while this build provides an identifiable communication method.”Security experts recommend keeping iPhones updated with the latest iOS security patches, avoiding untrusted login pages, and verifying website URLs before entering credentials. Organizations should also monitor for phishing activity and ensure employees are aware of impersonation attacks targeting cloud services and Apple accounts.

