Leaked DarkSword exploit kit fuels Chinese iOS credential theft wave

Censys links a Chinese-speaking operator running 100-plus fake login pages to the leaked DarkSword iOS exploit kit.

AppleThreat Staff
2 Min Read

A sprawling network of fake login pages is quietly delivering iOS spyware through a widely copied exploit kit. Security researchers say the operation spans more than 100 web properties and appears to be run by a Chinese-speaking group.

Attack surface management firm Censys traced the campaign to a leaked build of DarkSword, a full-chain iOS exploit kit first documented this year by Google Threat Intelligence Group, iVerify, and Lookout. The pages impersonate Amazon Web Services console logins and Apple ID sign-ins, and victims who land on them trigger a chain targeting iOS 18.4 through 18.7. The leak of the kit’s source code, Censys believes, has widened the circle of operators.

Successful hits deploy GHOSTBLADE, an information stealer that dumps keychain, iCloud, and Wi-Fi credentials before sweeping files off the device. Censys researcher Aidan Holland says the hosting concentrates in Hong Kong with reach into Japan, the United States, and Europe, and that panels use Chinese-language labels.

One C2 control panel carries a group name translated as Asia-Pacific Group alongside a Telegram contact channel, the first direct contact link recovered for the operator. Holland notes the cluster runs the leaked kit rather than a reimplementation, citing a shared staging-page hash and Russian-language code comments carried over from the original leak.

Evidence of reuse keeps surfacing. A separate Singapore host connected to this operator also served a Coruna admin panel, tying the group to that earlier kit as well. Prior reporting linked DarkSword to commercial surveillance vendors and state-backed campaigns in Saudi Arabia, Turkey, Malaysia, and Ukraine going back to November 2025.

Share This Article