Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Flowise RCE Flaws Let Attackers Execute Code on AI Workflow Servers
August 4, 2026
OWASP Releases Subtractive Security Top 10 to Reduce Cyber Risks
August 4, 2026
DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
August 4, 2026
Home/Threats/DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
Threats

DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts

Key Takeaways The DarkSword iOS exploit kit has significantly expanded its malicious infrastructure, now spanning 180 web properties and 27 hosts. This campaign specifically targets iPhones running...

David kimber
David kimber
August 4, 2026 5 Min Read
3 0

Key Takeaways

  • The DarkSword iOS exploit kit has significantly expanded its malicious infrastructure, now spanning 180 web properties and 27 hosts.
  • This campaign specifically targets iPhones running iOS versions 18.4 through 18.7.
  • The exploit kit leverages a six-vulnerability chain to bypass security measures and deploy GHOSTBLADE modules for extensive data exfiltration, including keychain, iCloud, and Wi-Fi credentials.
  • Attackers are rapidly rotating infrastructure, replacing servers within days while maintaining consistent malicious content.
  • Users are urged to update their iOS devices immediately and consider using Lockdown Mode to enhance protection against these highly targeted attacks.

DarkSword iOS Exploit Kit Expands Malicious Reach Across 180 Websites

The DarkSword iOS exploit kit, originating from a publicly leaked exploit chain, has evolved into a sophisticated and dynamic network of malicious web infrastructure. This campaign primarily targets iPhones operating on iOS versions 18.4 to 18.7, aiming to exfiltrate highly sensitive user data after victims are lured to compromised websites.

Table Of Content

  • Key Takeaways
  • DarkSword iOS Exploit Kit Expands Malicious Reach Across 180 Websites
  • Infrastructure and Evasion Tactics
  • Lures, Data Theft, and Defense
  • What You Should Do

The attack sequence is initiated when a user visits a deceptive website, which could be a fake sign-in portal, an iOS-themed page, or a compromised legitimate site. These sites surreptitiously load the exploit chain through hidden content. Once activated, DarkSword can circumvent iOS security protocols, gain access to device data, and then deploy GHOSTBLADE modules designed to harvest critical information such as keychain data, iCloud credentials, Wi-Fi passwords, and other sensitive files.

Infrastructure and Evasion Tactics

Researchers at Censys have been actively monitoring the growth of this infrastructure. Their analysis highlights the attackers’ agility in rapidly changing hosts and domains while retaining consistent web-page fingerprints. This tactic allows the operators to replace compromised servers within days, making traditional domain or IP-based blocking less effective, as Censys said in a report shared with Cyber Security News (CSN).

As of July 30, 2026, Censys observed 27 distinct hosts and 180 web properties associated with DarkSword. However, researchers emphasize that these numbers represent a fluid snapshot, continuously changing as the attackers adapt their infrastructure.

The DarkSword exploit kit is built upon a six-vulnerability chain, initially exposed via the ghh-jbDarkSword GitHub repository. This chain facilitates a browser-based attack flow, escalating from an initial web visit to deep device access, consistent with previous DarkSword attacks against high-value iPhone users. The malicious infrastructure observed includes fabricated AWS console pages and Apple ID credential-harvesting pages, alongside other ephemeral lure fronts. A notable example involved a Hong Kong server (103.106.190.217) simultaneously hosting an Apple-themed sign-in decoy and DarkSword staging content, demonstrating a combined approach to credential theft and exploit delivery on a single system.

To track the operation more effectively, researchers rely on stable page-body hashes rather than volatile domains. For instance, a DarkSword Admin panel hash was identified on seven hosts across Hong Kong, Japan, and the United States, even as five of these hosts changed within a week. The attackers also exposed several operator panels on non-standard ports, including 3000, 8443, and 8888. A specific pattern of five open ports was found on three Hong Kong Decode Dashboard hosts, while one Singapore host previously ran DarkSword concurrently with Coruna, an older iOS exploit framework.

Lures, Data Theft, and Defense

Upon landing on a malicious DarkSword page, victims are served a staging page that covertly loads a hidden iframe. This iframe then delivers exploit code specifically tailored to the victim’s iOS version. If the exploit succeeds, the GHOSTBLADE modules initiate data collection, targeting credentials, iCloud data, stored Wi-Fi passwords, and other files, which are then transmitted to attacker-controlled collection endpoints.

To hinder forensic analysis, the operators attempt to erase traces of their activity by deleting crash reports and the `RemoteLog.log` file before exiting. The Apple ID credential-harvesting decoy is particularly effective as it directly captures user credentials, mirroring the social engineering tactics seen in sophisticated Apple ID phishing campaigns.

What You Should Do

  • Update iOS Immediately: Ensure your iPhone is running the latest available iOS version to patch known vulnerabilities.
  • Enable Lockdown Mode: If immediate updates are not possible or if you are a high-risk individual, activate Apple’s Lockdown Mode for enhanced protection against targeted browser-based exploits.
  • Exercise Caution with Links: Be highly suspicious of unexpected sign-in pages or unsolicited links, especially those mimicking legitimate services like Apple ID or AWS.
  • Monitor Network Activity: For defenders, prioritize hunting for stable page-body hashes and the specific five-port Decode Dashboard pattern (8000, 8881, 8882, 8888, 9999, scoped to Hong Kong AS135357) rather than relying solely on ephemeral domain or IP blocklists.
  • Frequent Infrastructure Scans: Due to the rapid rotation of DarkSword hosts and web properties, security teams should conduct DarkSword exposure searches at least weekly.
  • Review IoCs: Utilize the provided Indicators of Compromise (IoCs) within controlled threat intelligence platforms (e.g., MISP, VirusTotal, SIEM) for proactive detection and blocking. Note that IP addresses and domains are intentionally defanged (e.g., `[.]`) to prevent accidental resolution or hyperlinking; re-fang only within secure environments.
Type Indicator Description
SHA-256 body hash 3c37835766ca615f5eb0e766b4000b43e896a420d575f02e1e160be5711e0782 Decode Dashboard panel
SHA-256 body hash 46a0bd09f145ab909e5bf45fafe906f452f06971bd227653f0c52af8e22da89e DarkSword Admin panel
SHA-256 body hash 273df85db2d449bbf32a44848877b07b417667eb96481ce37e46bf04dd6cc222 C2 Control Panel
SHA-256 body hash 50582f8d52e49f549615ec7cd68629b9f939a0cfc5c5408f324b2f1cff070e99 Exploit-chain staging page
SHA-256 body hash d37b6198034995b8642f78706e197b3ead3cdf125d7f9cf47a60dc7f9b8ef789 iCloud Apple credential-harvesting decoy
SHA-256 body hash 0a60f8ba0c0fa86f469c973cccc853f5d71a7ae8f2a9e057d6c7735d2c28070a Thorn C2 panel, co-resident and not confirmed as DarkSword
IP:Port 38.22.89.117:8888 DarkSword Admin panel
IP:Port 103.97.128.67:8888 DarkSword Admin panel
IP:Port 162.4.136.30:8888 DarkSword Admin panel
IP:Port 223.26.63.56:8888 DarkSword Admin panel
IP:Port 151.243.126.191:8888 DarkSword Admin panel
IP:Port 151.243.126.191:8443 Group page on DarkSword Admin host
IP:Port 107.175.49.181:3000 DarkSword Admin panel
IP:Port 103.238.129.112:3000 DarkSword Admin panel
IP address 103.226.155.200 Decode Dashboard host with five-port signature
IP address 103.226.155.201 Decode Dashboard host with five-port signature
IP address 202.8.120.249 Decode Dashboard host with five-port signature
IP address 103.106.190.217 C2 Control Panel and Apple ID decoy host
IP:Port 93.152.221.37:9999 Open directory exposing operator tooling
IP:Port 93.152.221.37:443 Thorn C2 panel
IP address 64.90.10.72 DarkSword staging lure front
IP address 38.76.185.209 Staging front with Xianyu-themed decoy
IP address 45.207.210.78 DarkSword staging lure front
IP address 45.197.237.210 DarkSword staging lure front
IP address 45.197.237.216 DarkSword staging lure front
IP address 156.224.25.7 DarkSword staging lure front
IP address 156.252.63.109 DarkSword staging lure front
IP address 43.255.156.130 DarkSword staging lure front
IP address 192.210.239.136 DarkSword staging lure front
IP address 177.3.41.61 DarkSword staging lure front
IP address 43.98.179.15 DarkSword staging lure front
IP address 136.244.95.4 DarkSword staging lure front
IP address 80.66.72.87 DarkSword staging lure front
IP address 2.26.22.89 DarkSword staging lure front
IP address 75.119.146.156 DarkSword staging lure front
Historical IP address 38.181.52.95 Singapore Coruna and DarkSword infrastructure, no longer active
Historical IP address 1.32.228.62 Previously documented DarkSword infrastructure
Historical IP address 202.162.109.71 Previously documented DarkSword infrastructure
Historical IP address 130.94.30.48 Previously documented DarkSword infrastructure
Historical IP address 38.12.47.193 Previously documented DarkSword infrastructure
Domain se006.vip Certificate SAN correlation to Decode Dashboard cluster
Domain ng28jt.xyz TLS certificate name on C2 Control Panel host
Domain jkonnet.buzz Base domain used in fake AWS console cluster
Domain tronide.cc Base domain hosting mixed administration subdomains
Domain myymk.cc Base domain hosting delivery subdomains
Domain ytl99.vip Base domain hosting delivery subdomains
Domain dcgfun.top Base domain hosting delivery subdomains
Historical domain static.cdncounter.net Former loader-delivery domain, now parked
Historical domain df45gdf48g.com Previously documented DarkSword domain
URL hxxps://t[.]me/YATA0000 Telegram contact link shown on C2 Control Panel
Network signature 8000, 8881, 8882, 8888, 9999 Decode Dashboard five-port pattern, scoped to Hong Kong AS135357
Panel title DarkSword Admin Operator panel title
Panel title Decode Dashboard Operator panel title
Panel title C2 Control Panel Operator panel title
Panel title Coruna Co-resident exploit-kit panel title
Panel title DarkSword DarkSword management panel title
Panel title iOS Exploit Dashboard Operator console title
File name index.html Staging-page file
File name ghostblade.js GHOSTBLADE payload module
File name keychaincopier.js Keychain collection module
File name wifipasswordsecurityd.js Wi-Fi credential-related module
File name iclouddumper.js iCloud data collection module
File name filedownloader.js File collection module
File name loader.js Exploit loader
File name wifipassworddump.js Wi-Fi password collection module
File name rcemodule.js Remote code execution module
File name rcemodule18.6.js iOS 18.6 remote code execution module
File name rceworker.js Remote code execution worker
File name rceworker18.6.js iOS 18.6 remote code execution worker
File name rceworker18.4.js iOS 18.4 remote code execution worker
File name rceloader.js Version-dispatch exploit loader
File name frame.html Hidden iframe loader
File name sbx1main.js Sandbox escape module
File name sbx0main18.4.js iOS 18.4 sandbox escape module
File name pemain.js Privilege escalation module
File artifact RemoteLog.log Log file deleted during anti-forensics cleanup
File artifact .bashhistory Exposed operator directory artifact
File artifact .ssh/authorized_keys Exposed SSH authorization file
Behavioral artifact jkcingapt SSH key comment recovered from exposed directory
Tool artifact .config/ffuf Cached ffuf configuration directory

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitPatchphishingSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

CISA Warns of Critical N-able N-central Auth Bypass (CVE-2023-47248) Exploited In Attacks

Next Post

OWASP Releases Subtractive Security Top 10 to Reduce Cyber Risks

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Roblox Malware Steals Desktop Streams and Webcam Footage
August 4, 2026
Keyv npm package compromised in supply chain attack
August 4, 2026
Cybercriminals Exploit ChatGPT for Scam Operations, OpenAI Reports
August 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us