A mysterious Chinese threat actor has been spotted orchestrating campaigns against iOS devices using a publicly accessible version of the DarkSword exploit kit. The attack surface management platform Censys revealed that this individual operated more than 100 web properties, with most being fake Amazon Web Services (AWS) sign-in pages hosted on a domain also featuring the exploit toolkit. DarkSword, discovered earlier this year by GTIG, iVerify, and Lookout, is a full-chain exploit kit believed to have been utilized by commercial surveillance vendors and suspected state-sponsored actors targeting various locations since November 2025.

The kit specifically targets iOS versions 18.4 through 18.7.

Censys' latest findings show that a panel called "DarkSword Admin" matches seven hosts across three countries as of July 30, 2026, including a Singapore-based host ("38.181.52[. ]95") with three distinct exploit-panel front ends and a Hong Kong host bundling an Apple ID credential-harvesting decoy ("103.106.190[.]217"). One login panel on the IP address "38.22.89[.

]117:8888" features Chinese-language field labels for "username," "password," and "Log in." The other six IP addresses are below - 103.97.128[. ]67:8888, 162.4.136[. ]30:8888, 223.26.63[.

]56:8888, 151.243.126[. ]191:8888, 107.175.49[. ]181:3000, and 103.238.129[.]112:3000. The 'C2 Control Panel' login stands out visually from the other two panels: its near-black background (#06060d), red accent (#ff0050), animated particle-canvas effect, direct group name rendered on the page (亚太集团, 'Asia-Pacific Group'), and visible Telegram contact link (hxxps://t[.

]me/YATA0000).