A Chinese threat operator has spread a DarkSword iOS exploit kit across 180 websites, based on infrastructure scanning data. The operation involves rotating hosts, fake cloud and Apple ID login pages, and multiple control panels for managing stolen data. The kit reportedly combines six vulnerabilities to bypass security measures, escape the sandbox, and deploy credential-stealing modules.
Its source code was publicly leaked through ghh-jb/DarkSword on GitHub, allowing multiple operators to adopt it without knowledge of its true origins. The latest cluster is larger and more active than previous DarkSword deployments, covering 27 hosts and 180 web properties as of July 30, 2026.
However, researchers determined this to be a conservative estimate due to frequent domain name changes and infrastructure replacements by attackers before automated fingerprinting tools can identify them. The campaign primarily utilizes fake AWS console pages, iOS-themed lures, and recently Apple ID phishing pages in its attack flow. The most reliable tracking signal isn't a domain name or port number; it's static webpage body hashes reused across the infrastructure.
One DarkSword admin login page hash, 46a0bd09f145ab909e5bf45fafe906f452f06971bd227653f0c52af8e22da89e, surfaced on seven hosts scattered across Hong Kong, Japan, and the United States. The loader fetches the iOS version from the browser's User Agent string, choosing appropriate exploit workers based on the device's version.












