DarkSword has expanded from a leaked iOS exploit chain into a broad and fast-changing network of malicious web infrastructure.
The campaign targets iPhones running iOS 18.4 through 18.7 and is designed to steal highly sensitive data after a victim visits a lure site.
The attack begins with fake sign-in pages, iOS-themed sites, and compromised web properties that load the exploit chain through hidden content.
Once triggered, DarkSword can bypass protections, access device data, and deliver GHOSTBLADE modules built to collect keychain, iCloud, Wi-Fi, and other files.
Researchers at Censys identified the latest infrastructure growth while tracking stable web-page fingerprints across rapidly changing hosts and domains.
Their findings show that the operators are replacing servers in days while retaining recognizable panel and staging-page content.
Censys said in a report shared with Cyber Security News (CSN) that the scale makes this campaign especially concerning.
Censys observed 27 hosts and 180 web properties carrying the DarkSword label as of July 30, 2026, though the researchers stressed that this represents a changing snapshot rather than a fixed list.
DarkSword is a six-vulnerability exploit chain publicly leaked through the ghh-jbDarkSword GitHub repository.
It uses browser-based code to move from a victim’s visit to deeper device access, following the same broad threat model described in previous DarkSword exploit coverage of attacks against high-value iPhone users.
The infrastructure included fake AWS console pages, Apple ID credential-harvesting pages, and other disposable lure fronts.
One Hong Kong server, 103.106.190.217, hosted both an Apple-themed sign-in decoy and DarkSword staging content, combining credential theft and exploit delivery on the same system.
The body hashes offer a stronger way to follow the operation than domains alone. A DarkSword Admin panel hash appeared on seven hosts in Hong Kong, Japan, and the United States, even as five of those hosts changed within a week.
The actors also exposed several operator panels on unusual ports, including 3000, 8443, and 8888.
Three Hong Kong Decode Dashboard hosts shared a five-port pattern, while one Singapore host previously ran DarkSword alongside Coruna, an older iOS exploit framework discussed in earlier Coruna exploit analysis.
A victim who reaches a malicious page is served a staging page that silently loads a hidden frame and selects exploit code based on the iOS version.
If the attack works, GHOSTBLADE components collect credentials, cloud data, saved Wi-Fi passwords, and files before sending the data to attacker-controlled collection endpoints.
The operators also try to remove signs of compromise by deleting crash reports and RemoteLog.log before exiting.
Their Apple ID decoy is particularly notable because it could capture credentials directly, a tactic that mirrors the social-engineering risk seen in Apple ID phishing campaigns.
For defenders, the report recommends hunting stable page-body hashes and the full five-port Decode Dashboard pattern instead of relying only on domain or IP blocklists.
Teams should rerun DarkSword exposure searches at least weekly because the hosts and web properties rotate quickly. iPhone users should install the latest available iOS updates without delay.
Where an immediate update is not possible, Lockdown Mode can add protection against highly targeted browser-based attacks, while unexpected sign-in pages and unsolicited links should be treated as suspicious.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| SHA-256 body hash | 3c37835766ca615f5eb0e766b4000b43e896a420d575f02e1e160be5711e0782 | Decode Dashboard panel |
| SHA-256 body hash | 46a0bd09f145ab909e5bf45fafe906f452f06971bd227653f0c52af8e22da89e | DarkSword Admin panel |
| SHA-256 body hash | 273df85db2d449bbf32a44848877b07b417667eb96481ce37e46bf04dd6cc222 | C2 Control Panel |
| SHA-256 body hash | 50582f8d52e49f549615ec7cd68629b9f939a0cfc5c5408f324b2f1cff070e99 | Exploit-chain staging page |
| SHA-256 body hash | d37b6198034995b8642f78706e197b3ead3cdf125d7f9cf47a60dc7f9b8ef789 | iCloud Apple credential-harvesting decoy |
| SHA-256 body hash | 0a60f8ba0c0fa86f469c973cccc853f5d71a7ae8f2a9e057d6c7735d2c28070a | Thorn C2 panel, co-resident and not confirmed as DarkSword |
| IP:Port | 38.22.89.117:8888 | DarkSword Admin panel |
| IP:Port | 103.97.128.67:8888 | DarkSword Admin panel |
| IP:Port | 162.4.136.30:8888 | DarkSword Admin panel |
| IP:Port | 223.26.63.56:8888 | DarkSword Admin panel |
| IP:Port | 151.243.126.191:8888 | DarkSword Admin panel |
| IP:Port | 151.243.126.191:8443 | Group page on DarkSword Admin host |
| IP:Port | 107.175.49.181:3000 | DarkSword Admin panel |
| IP:Port | 103.238.129.112:3000 | DarkSword Admin panel |
| IP address | 103.226.155.200 | Decode Dashboard host with five-port signature |
| IP address | 103.226.155.201 | Decode Dashboard host with five-port signature |
| IP address | 202.8.120.249 | Decode Dashboard host with five-port signature |
| IP address | 103.106.190.217 | C2 Control Panel and Apple ID decoy host |
| IP:Port | 93.152.221.37:9999 | Open directory exposing operator tooling |
| IP:Port | 93.152.221.37:443 | Thorn C2 panel |
| IP address | 64.90.10.72 | DarkSword staging lure front |
| IP address | 38.76.185.209 | Staging front with Xianyu-themed decoy |
| IP address | 45.207.210.78 | DarkSword staging lure front |
| IP address | 45.197.237.210 | DarkSword staging lure front |
| IP address | 45.197.237.216 | DarkSword staging lure front |
| IP address | 156.224.25.7 | DarkSword staging lure front |
| IP address | 156.252.63.109 | DarkSword staging lure front |
| IP address | 43.255.156.130 | DarkSword staging lure front |
| IP address | 192.210.239.136 | DarkSword staging lure front |
| IP address | 177.3.41.61 | DarkSword staging lure front |
| IP address | 43.98.179.15 | DarkSword staging lure front |
| IP address | 136.244.95.4 | DarkSword staging lure front |
| IP address | 80.66.72.87 | DarkSword staging lure front |
| IP address | 2.26.22.89 | DarkSword staging lure front |
| IP address | 75.119.146.156 | DarkSword staging lure front |
| Historical IP address | 38.181.52.95 | Singapore Coruna and DarkSword infrastructure, no longer active |
| Historical IP address | 1.32.228.62 | Previously documented DarkSword infrastructure |
| Historical IP address | 202.162.109.71 | Previously documented DarkSword infrastructure |
| Historical IP address | 130.94.30.48 | Previously documented DarkSword infrastructure |
| Historical IP address | 38.12.47.193 | Previously documented DarkSword infrastructure |
| Domain | se006.vip | Certificate SAN correlation to Decode Dashboard cluster |
| Domain | ng28jt.xyz | TLS certificate name on C2 Control Panel host |
| Domain | jkonnet.buzz | Base domain used in fake AWS console cluster |
| Domain | tronide.cc | Base domain hosting mixed administration subdomains |
| Domain | myymk.cc | Base domain hosting delivery subdomains |
| Domain | ytl99.vip | Base domain hosting delivery subdomains |
| Domain | dcgfun.top | Base domain hosting delivery subdomains |
| Historical domain | static.cdncounter.net | Former loader-delivery domain, now parked |
| Historical domain | df45gdf48g.com | Previously documented DarkSword domain |
| URL | hxxps://t[.]me/YATA0000 | Telegram contact link shown on C2 Control Panel |
| Network signature | 8000, 8881, 8882, 8888, 9999 | Decode Dashboard five-port pattern, scoped to Hong Kong AS135357 |
| Panel title | DarkSword Admin | Operator panel title |
| Panel title | Decode Dashboard | Operator panel title |
| Panel title | C2 Control Panel | Operator panel title |
| Panel title | Coruna | Co-resident exploit-kit panel title |
| Panel title | DarkSword | DarkSword management panel title |
| Panel title | iOS Exploit Dashboard | Operator console title |
| File name | index.html | Staging-page file |
| File name | ghostblade.js | GHOSTBLADE payload module |
| File name | keychaincopier.js | Keychain collection module |
| File name | wifipasswordsecurityd.js | Wi-Fi credential-related module |
| File name | iclouddumper.js | iCloud data collection module |
| File name | filedownloader.js | File collection module |
| File name | loader.js | Exploit loader |
| File name | wifipassworddump.js | Wi-Fi password collection module |
| File name | rcemodule.js | Remote code execution module |
| File name | rcemodule18.6.js | iOS 18.6 remote code execution module |
| File name | rceworker.js | Remote code execution worker |
| File name | rceworker18.6.js | iOS 18.6 remote code execution worker |
| File name | rceworker18.4.js | iOS 18.4 remote code execution worker |
| File name | rceloader.js | Version-dispatch exploit loader |
| File name | frame.html | Hidden iframe loader |
| File name | sbx1main.js | Sandbox escape module |
| File name | sbx0main18.4.js | iOS 18.4 sandbox escape module |
| File name | pemain.js | Privilege escalation module |
| File artifact | RemoteLog.log | Log file deleted during anti-forensics cleanup |
| File artifact | .bashhistory | Exposed operator directory artifact |
| File artifact | .ssh/authorized_keys | Exposed SSH authorization file |
| Behavioral artifact | jkcingapt | SSH key comment recovered from exposed directory |
| Tool artifact | .config/ffuf | Cached ffuf configuration directory |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN
CISA's latest advisory for red teams warns critical infrastructure operators that security systems can fail…
Alice, the AI trust, safety, and security company formerly known as ActiveFence, has closed a…
SynkLoader is using Microsoft Teams conversations to turn routine IT support requests into a route…
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real…
WhatsApp has confirmed that more than 1 billion people now use passkeys to log into…
ASOS US Sales LLC reported unauthorized access to customer accounts using credentials obtained from outside…