DarkSword iOS Exploit Kit Spreads to 180 Websites and 27 Hosts
Key Takeaways The DarkSword iOS exploit kit has significantly expanded its malicious infrastructure, now spanning 180 web properties and 27 hosts. This campaign specifically targets iPhones running...
Key Takeaways
- The DarkSword iOS exploit kit has significantly expanded its malicious infrastructure, now spanning 180 web properties and 27 hosts.
- This campaign specifically targets iPhones running iOS versions 18.4 through 18.7.
- The exploit kit leverages a six-vulnerability chain to bypass security measures and deploy GHOSTBLADE modules for extensive data exfiltration, including keychain, iCloud, and Wi-Fi credentials.
- Attackers are rapidly rotating infrastructure, replacing servers within days while maintaining consistent malicious content.
- Users are urged to update their iOS devices immediately and consider using Lockdown Mode to enhance protection against these highly targeted attacks.
DarkSword iOS Exploit Kit Expands Malicious Reach Across 180 Websites
The DarkSword iOS exploit kit, originating from a publicly leaked exploit chain, has evolved into a sophisticated and dynamic network of malicious web infrastructure. This campaign primarily targets iPhones operating on iOS versions 18.4 to 18.7, aiming to exfiltrate highly sensitive user data after victims are lured to compromised websites.
Table Of Content
The attack sequence is initiated when a user visits a deceptive website, which could be a fake sign-in portal, an iOS-themed page, or a compromised legitimate site. These sites surreptitiously load the exploit chain through hidden content. Once activated, DarkSword can circumvent iOS security protocols, gain access to device data, and then deploy GHOSTBLADE modules designed to harvest critical information such as keychain data, iCloud credentials, Wi-Fi passwords, and other sensitive files.
Infrastructure and Evasion Tactics
Researchers at Censys have been actively monitoring the growth of this infrastructure. Their analysis highlights the attackers’ agility in rapidly changing hosts and domains while retaining consistent web-page fingerprints. This tactic allows the operators to replace compromised servers within days, making traditional domain or IP-based blocking less effective, as Censys said in a report shared with Cyber Security News (CSN).
As of July 30, 2026, Censys observed 27 distinct hosts and 180 web properties associated with DarkSword. However, researchers emphasize that these numbers represent a fluid snapshot, continuously changing as the attackers adapt their infrastructure.
The DarkSword exploit kit is built upon a six-vulnerability chain, initially exposed via the ghh-jbDarkSword GitHub repository. This chain facilitates a browser-based attack flow, escalating from an initial web visit to deep device access, consistent with previous DarkSword attacks against high-value iPhone users. The malicious infrastructure observed includes fabricated AWS console pages and Apple ID credential-harvesting pages, alongside other ephemeral lure fronts. A notable example involved a Hong Kong server (103.106.190.217) simultaneously hosting an Apple-themed sign-in decoy and DarkSword staging content, demonstrating a combined approach to credential theft and exploit delivery on a single system.
To track the operation more effectively, researchers rely on stable page-body hashes rather than volatile domains. For instance, a DarkSword Admin panel hash was identified on seven hosts across Hong Kong, Japan, and the United States, even as five of these hosts changed within a week. The attackers also exposed several operator panels on non-standard ports, including 3000, 8443, and 8888. A specific pattern of five open ports was found on three Hong Kong Decode Dashboard hosts, while one Singapore host previously ran DarkSword concurrently with Coruna, an older iOS exploit framework.
Lures, Data Theft, and Defense
Upon landing on a malicious DarkSword page, victims are served a staging page that covertly loads a hidden iframe. This iframe then delivers exploit code specifically tailored to the victim’s iOS version. If the exploit succeeds, the GHOSTBLADE modules initiate data collection, targeting credentials, iCloud data, stored Wi-Fi passwords, and other files, which are then transmitted to attacker-controlled collection endpoints.
To hinder forensic analysis, the operators attempt to erase traces of their activity by deleting crash reports and the `RemoteLog.log` file before exiting. The Apple ID credential-harvesting decoy is particularly effective as it directly captures user credentials, mirroring the social engineering tactics seen in sophisticated Apple ID phishing campaigns.
What You Should Do
- Update iOS Immediately: Ensure your iPhone is running the latest available iOS version to patch known vulnerabilities.
- Enable Lockdown Mode: If immediate updates are not possible or if you are a high-risk individual, activate Apple’s Lockdown Mode for enhanced protection against targeted browser-based exploits.
- Exercise Caution with Links: Be highly suspicious of unexpected sign-in pages or unsolicited links, especially those mimicking legitimate services like Apple ID or AWS.
- Monitor Network Activity: For defenders, prioritize hunting for stable page-body hashes and the specific five-port Decode Dashboard pattern (8000, 8881, 8882, 8888, 9999, scoped to Hong Kong AS135357) rather than relying solely on ephemeral domain or IP blocklists.
- Frequent Infrastructure Scans: Due to the rapid rotation of DarkSword hosts and web properties, security teams should conduct DarkSword exposure searches at least weekly.
- Review IoCs: Utilize the provided Indicators of Compromise (IoCs) within controlled threat intelligence platforms (e.g., MISP, VirusTotal, SIEM) for proactive detection and blocking. Note that IP addresses and domains are intentionally defanged (e.g., `[.]`) to prevent accidental resolution or hyperlinking; re-fang only within secure environments.
| Type | Indicator | Description |
|---|---|---|
| SHA-256 body hash | 3c37835766ca615f5eb0e766b4000b43e896a420d575f02e1e160be5711e0782 |
Decode Dashboard panel |
| SHA-256 body hash | 46a0bd09f145ab909e5bf45fafe906f452f06971bd227653f0c52af8e22da89e |
DarkSword Admin panel |
| SHA-256 body hash | 273df85db2d449bbf32a44848877b07b417667eb96481ce37e46bf04dd6cc222 |
C2 Control Panel |
| SHA-256 body hash | 50582f8d52e49f549615ec7cd68629b9f939a0cfc5c5408f324b2f1cff070e99 |
Exploit-chain staging page |
| SHA-256 body hash | d37b6198034995b8642f78706e197b3ead3cdf125d7f9cf47a60dc7f9b8ef789 |
iCloud Apple credential-harvesting decoy |
| SHA-256 body hash | 0a60f8ba0c0fa86f469c973cccc853f5d71a7ae8f2a9e057d6c7735d2c28070a |
Thorn C2 panel, co-resident and not confirmed as DarkSword |
| IP:Port | 38.22.89.117:8888 |
DarkSword Admin panel |
| IP:Port | 103.97.128.67:8888 |
DarkSword Admin panel |
| IP:Port | 162.4.136.30:8888 |
DarkSword Admin panel |
| IP:Port | 223.26.63.56:8888 |
DarkSword Admin panel |
| IP:Port | 151.243.126.191:8888 |
DarkSword Admin panel |
| IP:Port | 151.243.126.191:8443 |
Group page on DarkSword Admin host |
| IP:Port | 107.175.49.181:3000 |
DarkSword Admin panel |
| IP:Port | 103.238.129.112:3000 |
DarkSword Admin panel |
| IP address | 103.226.155.200 |
Decode Dashboard host with five-port signature |
| IP address | 103.226.155.201 |
Decode Dashboard host with five-port signature |
| IP address | 202.8.120.249 |
Decode Dashboard host with five-port signature |
| IP address | 103.106.190.217 |
C2 Control Panel and Apple ID decoy host |
| IP:Port | 93.152.221.37:9999 |
Open directory exposing operator tooling |
| IP:Port | 93.152.221.37:443 |
Thorn C2 panel |
| IP address | 64.90.10.72 |
DarkSword staging lure front |
| IP address | 38.76.185.209 |
Staging front with Xianyu-themed decoy |
| IP address | 45.207.210.78 |
DarkSword staging lure front |
| IP address | 45.197.237.210 |
DarkSword staging lure front |
| IP address | 45.197.237.216 |
DarkSword staging lure front |
| IP address | 156.224.25.7 |
DarkSword staging lure front |
| IP address | 156.252.63.109 |
DarkSword staging lure front |
| IP address | 43.255.156.130 |
DarkSword staging lure front |
| IP address | 192.210.239.136 |
DarkSword staging lure front |
| IP address | 177.3.41.61 |
DarkSword staging lure front |
| IP address | 43.98.179.15 |
DarkSword staging lure front |
| IP address | 136.244.95.4 |
DarkSword staging lure front |
| IP address | 80.66.72.87 |
DarkSword staging lure front |
| IP address | 2.26.22.89 |
DarkSword staging lure front |
| IP address | 75.119.146.156 |
DarkSword staging lure front |
| Historical IP address | 38.181.52.95 |
Singapore Coruna and DarkSword infrastructure, no longer active |
| Historical IP address | 1.32.228.62 |
Previously documented DarkSword infrastructure |
| Historical IP address | 202.162.109.71 |
Previously documented DarkSword infrastructure |
| Historical IP address | 130.94.30.48 |
Previously documented DarkSword infrastructure |
| Historical IP address | 38.12.47.193 |
Previously documented DarkSword infrastructure |
| Domain | se006.vip |
Certificate SAN correlation to Decode Dashboard cluster |
| Domain | ng28jt.xyz |
TLS certificate name on C2 Control Panel host |
| Domain | jkonnet.buzz |
Base domain used in fake AWS console cluster |
| Domain | tronide.cc |
Base domain hosting mixed administration subdomains |
| Domain | myymk.cc |
Base domain hosting delivery subdomains |
| Domain | ytl99.vip |
Base domain hosting delivery subdomains |
| Domain | dcgfun.top |
Base domain hosting delivery subdomains |
| Historical domain | static.cdncounter.net |
Former loader-delivery domain, now parked |
| Historical domain | df45gdf48g.com |
Previously documented DarkSword domain |
| URL | hxxps://t[.]me/YATA0000 |
Telegram contact link shown on C2 Control Panel |
| Network signature | 8000, 8881, 8882, 8888, 9999 |
Decode Dashboard five-port pattern, scoped to Hong Kong AS135357 |
| Panel title | DarkSword Admin |
Operator panel title |
| Panel title | Decode Dashboard |
Operator panel title |
| Panel title | C2 Control Panel |
Operator panel title |
| Panel title | Coruna |
Co-resident exploit-kit panel title |
| Panel title | DarkSword |
DarkSword management panel title |
| Panel title | iOS Exploit Dashboard |
Operator console title |
| File name | index.html |
Staging-page file |
| File name | ghostblade.js |
GHOSTBLADE payload module |
| File name | keychaincopier.js |
Keychain collection module |
| File name | wifipasswordsecurityd.js |
Wi-Fi credential-related module |
| File name | iclouddumper.js |
iCloud data collection module |
| File name | filedownloader.js |
File collection module |
| File name | loader.js |
Exploit loader |
| File name | wifipassworddump.js |
Wi-Fi password collection module |
| File name | rcemodule.js |
Remote code execution module |
| File name | rcemodule18.6.js |
iOS 18.6 remote code execution module |
| File name | rceworker.js |
Remote code execution worker |
| File name | rceworker18.6.js |
iOS 18.6 remote code execution worker |
| File name | rceworker18.4.js |
iOS 18.4 remote code execution worker |
| File name | rceloader.js |
Version-dispatch exploit loader |
| File name | frame.html |
Hidden iframe loader |
| File name | sbx1main.js |
Sandbox escape module |
| File name | sbx0main18.4.js |
iOS 18.4 sandbox escape module |
| File name | pemain.js |
Privilege escalation module |
| File artifact | RemoteLog.log |
Log file deleted during anti-forensics cleanup |
| File artifact | .bashhistory |
Exposed operator directory artifact |
| File artifact | .ssh/authorized_keys |
Exposed SSH authorization file |
| Behavioral artifact | jkcingapt |
SSH key comment recovered from exposed directory |
| Tool artifact | .config/ffuf |
Cached ffuf configuration directory |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.