Cyber Security News

DarkSword iOS Exploit Kit Spreads Across 180 Web Properties and 27 Hosts

DarkSword has expanded from a leaked iOS exploit chain into a broad and fast-changing network of malicious web infrastructure.

The campaign targets iPhones running iOS 18.4 through 18.7 and is designed to steal highly sensitive data after a victim visits a lure site.

The attack begins with fake sign-in pages, iOS-themed sites, and compromised web properties that load the exploit chain through hidden content.

Once triggered, DarkSword can bypass protections, access device data, and deliver GHOSTBLADE modules built to collect keychain, iCloud, Wi-Fi, and other files.

Researchers at Censys identified the latest infrastructure growth while tracking stable web-page fingerprints across rapidly changing hosts and domains.

Their findings show that the operators are replacing servers in days while retaining recognizable panel and staging-page content.

Censys said in a report shared with Cyber Security News (CSN) that the scale makes this campaign especially concerning.

Censys observed 27 hosts and 180 web properties carrying the DarkSword label as of July 30, 2026, though the researchers stressed that this represents a changing snapshot rather than a fixed list.

DarkSword iOS Exploit Kit

DarkSword is a six-vulnerability exploit chain publicly leaked through the ghh-jbDarkSword GitHub repository.

DarkSword Admin login panel (Source – Censys)

It uses browser-based code to move from a victim’s visit to deeper device access, following the same broad threat model described in previous DarkSword exploit coverage of attacks against high-value iPhone users.

The infrastructure included fake AWS console pages, Apple ID credential-harvesting pages, and other disposable lure fronts.

One Hong Kong server, 103.106.190.217, hosted both an Apple-themed sign-in decoy and DarkSword staging content, combining credential theft and exploit delivery on the same system.

The body hashes offer a stronger way to follow the operation than domains alone. A DarkSword Admin panel hash appeared on seven hosts in Hong Kong, Japan, and the United States, even as five of those hosts changed within a week.

The actors also exposed several operator panels on unusual ports, including 3000, 8443, and 8888.

Three Hong Kong Decode Dashboard hosts shared a five-port pattern, while one Singapore host previously ran DarkSword alongside Coruna, an older iOS exploit framework discussed in earlier Coruna exploit analysis.

Lures, Data Theft, and Defense

A victim who reaches a malicious page is served a staging page that silently loads a hidden frame and selects exploit code based on the iOS version.

If the attack works, GHOSTBLADE components collect credentials, cloud data, saved Wi-Fi passwords, and files before sending the data to attacker-controlled collection endpoints.

The DarkSword operator attack flow (Source – Censys)

The operators also try to remove signs of compromise by deleting crash reports and RemoteLog.log before exiting.

Their Apple ID decoy is particularly notable because it could capture credentials directly, a tactic that mirrors the social-engineering risk seen in Apple ID phishing campaigns.

For defenders, the report recommends hunting stable page-body hashes and the full five-port Decode Dashboard pattern instead of relying only on domain or IP blocklists.

The ‘iCloud – Apple’ credential-harvesting page (Source – Censys)

Teams should rerun DarkSword exposure searches at least weekly because the hosts and web properties rotate quickly. iPhone users should install the latest available iOS updates without delay.

Where an immediate update is not possible, Lockdown Mode can add protection against highly targeted browser-based attacks, while unexpected sign-in pages and unsolicited links should be treated as suspicious.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
SHA-256 body hash3c37835766ca615f5eb0e766b4000b43e896a420d575f02e1e160be5711e0782Decode Dashboard panel
SHA-256 body hash46a0bd09f145ab909e5bf45fafe906f452f06971bd227653f0c52af8e22da89eDarkSword Admin panel
SHA-256 body hash273df85db2d449bbf32a44848877b07b417667eb96481ce37e46bf04dd6cc222C2 Control Panel
SHA-256 body hash50582f8d52e49f549615ec7cd68629b9f939a0cfc5c5408f324b2f1cff070e99Exploit-chain staging page
SHA-256 body hashd37b6198034995b8642f78706e197b3ead3cdf125d7f9cf47a60dc7f9b8ef789iCloud Apple credential-harvesting decoy
SHA-256 body hash0a60f8ba0c0fa86f469c973cccc853f5d71a7ae8f2a9e057d6c7735d2c28070aThorn C2 panel, co-resident and not confirmed as DarkSword
IP:Port38.22.89.117:8888DarkSword Admin panel
IP:Port103.97.128.67:8888DarkSword Admin panel
IP:Port162.4.136.30:8888DarkSword Admin panel
IP:Port223.26.63.56:8888DarkSword Admin panel
IP:Port151.243.126.191:8888DarkSword Admin panel
IP:Port151.243.126.191:8443Group page on DarkSword Admin host
IP:Port107.175.49.181:3000DarkSword Admin panel
IP:Port103.238.129.112:3000DarkSword Admin panel
IP address103.226.155.200Decode Dashboard host with five-port signature
IP address103.226.155.201Decode Dashboard host with five-port signature
IP address202.8.120.249Decode Dashboard host with five-port signature
IP address103.106.190.217C2 Control Panel and Apple ID decoy host
IP:Port93.152.221.37:9999Open directory exposing operator tooling
IP:Port93.152.221.37:443Thorn C2 panel
IP address64.90.10.72DarkSword staging lure front
IP address38.76.185.209Staging front with Xianyu-themed decoy
IP address45.207.210.78DarkSword staging lure front
IP address45.197.237.210DarkSword staging lure front
IP address45.197.237.216DarkSword staging lure front
IP address156.224.25.7DarkSword staging lure front
IP address156.252.63.109DarkSword staging lure front
IP address43.255.156.130DarkSword staging lure front
IP address192.210.239.136DarkSword staging lure front
IP address177.3.41.61DarkSword staging lure front
IP address43.98.179.15DarkSword staging lure front
IP address136.244.95.4DarkSword staging lure front
IP address80.66.72.87DarkSword staging lure front
IP address2.26.22.89DarkSword staging lure front
IP address75.119.146.156DarkSword staging lure front
Historical IP address38.181.52.95Singapore Coruna and DarkSword infrastructure, no longer active
Historical IP address1.32.228.62Previously documented DarkSword infrastructure
Historical IP address202.162.109.71Previously documented DarkSword infrastructure
Historical IP address130.94.30.48Previously documented DarkSword infrastructure
Historical IP address38.12.47.193Previously documented DarkSword infrastructure
Domainse006.vipCertificate SAN correlation to Decode Dashboard cluster
Domainng28jt.xyzTLS certificate name on C2 Control Panel host
Domainjkonnet.buzzBase domain used in fake AWS console cluster
Domaintronide.ccBase domain hosting mixed administration subdomains
Domainmyymk.ccBase domain hosting delivery subdomains
Domainytl99.vipBase domain hosting delivery subdomains
Domaindcgfun.topBase domain hosting delivery subdomains
Historical domainstatic.cdncounter.netFormer loader-delivery domain, now parked
Historical domaindf45gdf48g.comPreviously documented DarkSword domain
URLhxxps://t[.]me/YATA0000Telegram contact link shown on C2 Control Panel
Network signature8000, 8881, 8882, 8888, 9999Decode Dashboard five-port pattern, scoped to Hong Kong AS135357
Panel titleDarkSword AdminOperator panel title
Panel titleDecode DashboardOperator panel title
Panel titleC2 Control PanelOperator panel title
Panel titleCorunaCo-resident exploit-kit panel title
Panel titleDarkSwordDarkSword management panel title
Panel titleiOS Exploit DashboardOperator console title
File nameindex.htmlStaging-page file
File nameghostblade.jsGHOSTBLADE payload module
File namekeychaincopier.jsKeychain collection module
File namewifipasswordsecurityd.jsWi-Fi credential-related module
File nameiclouddumper.jsiCloud data collection module
File namefiledownloader.jsFile collection module
File nameloader.jsExploit loader
File namewifipassworddump.jsWi-Fi password collection module
File namercemodule.jsRemote code execution module
File namercemodule18.6.jsiOS 18.6 remote code execution module
File namerceworker.jsRemote code execution worker
File namerceworker18.6.jsiOS 18.6 remote code execution worker
File namerceworker18.4.jsiOS 18.4 remote code execution worker
File namerceloader.jsVersion-dispatch exploit loader
File nameframe.htmlHidden iframe loader
File namesbx1main.jsSandbox escape module
File namesbx0main18.4.jsiOS 18.4 sandbox escape module
File namepemain.jsPrivilege escalation module
File artifactRemoteLog.logLog file deleted during anti-forensics cleanup
File artifact.bashhistoryExposed operator directory artifact
File artifact.ssh/authorized_keysExposed SSH authorization file
Behavioral artifactjkcingaptSSH key comment recovered from exposed directory
Tool artifact.config/ffufCached ffuf configuration directory

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

CISA Red Team Breaches Critical Infrastructure to Reveal SOC and Cloud Security Gaps

CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…

5 hours ago

AI Security Startup Alice Raises $140 Million as Enterprise AI Threats Surge

Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…

6 hours ago

SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams

SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…

7 hours ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…

7 hours ago

WhatsApp Passkeys Reach 1 Billion Users as Two-Step Verification Gets Stronger Passwords

WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…

7 hours ago

ASOS Warns Customer Accounts Were Accessed Using Compromised Login Credentials

ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…

7 hours ago