DarkSword iOS Exploit Kit Targets iPhones via 180 Malicious Websites
Security researchers at Censys have uncovered a large‑scale cyber‑espionage campaign that uses the DarkSword iOS exploit kit to compromise iPhones running iOS 18.4‑18.7. The operation spreads through more than 180 compromised web properties and 27 distinct hosts, serving fake login pages that mimic services such as Amazon Web Services and Apple ID to lure victims.
When a user visits one of these lure sites, the DarkSword exploit chain bypasses device protections and installs the GHOSTBLADE stealer, which extracts keychain credentials, iCloud data and Wi‑Fi passwords. The infrastructure is globally distributed, with admin hosts located in Hong Kong, the United States, Japan and Singapore. The campaign is attributed to a Chinese‑speaking actor identified as the “Asia‑Pacific Group,” which coordinates via a Telegram contact.
Censys observed rapid turnover of domains and servers, with seven admin panels operating on ports 3000, 8443 and 8888, while maintaining recognizable staging‑page fingerprints. The scale and speed of the campaign raise significant concerns for iPhone users and the broader mobile security landscape.
Entities: Asia‑Pacific Group · Censys · DarkSword iOS Exploit Kit · GHOSTBLADE Stealer · Hong Kong