A Chinese-speaking threat operator has deployed the leaked DarkSword iOS exploit kit across at least 180 web properties, according to infrastructure scanning data.
The activity involves rotating hosts, fake cloud and Apple ID login pages, and multiple control panels used to manage stolen data.
DarkSword is a commercial iOS exploit chain targeting iOS 18.4 through 18.7. The kit reportedly combines six vulnerabilities to bypass security controls, escape the sandbox, and deploy credential-stealing modules.
Its source code was publicly leaked through the ghh-jb/DarkSword GitHub repository, enabling several unrelated operators to adopt it.
The latest cluster appears larger and more active than earlier DarkSword deployments. As of July 30, 2026, the Censys DarkSword threat label covered 27 hosts and 180 web properties.
However, researchers assessed this as a minimum figure because operators frequently replace domains and hosting infrastructure before automated fingerprints can identify them.
The campaign primarily uses fake AWS console pages, iOS-themed lures, and, more recently, Apple ID phishing pages.
Researchers identified a host at 103.106.190[.]217 that served both an Apple-branded credential-harvesting page and DarkSword exploit staging content.
This co-hosting is notable because earlier infrastructure separated phishing pages from exploit delivery servers.
Chinese Operator Deploys DarkSword
The most reliable tracking signal is not a domain name or port number, but static webpage body hashes reused across the infrastructure.
One DarkSword Admin login page hash, 46a0bd09f145ab909e5bf45fafe906f452f06971bd227653f0c52af8e22da89e, appeared on seven hosts across Hong Kong, Japan, and the United States.
These hosts used different providers and exposed the panel over ports including 3000, 8443, and 8888.
Five of the seven hosts were new within one week, demonstrating rapid infrastructure churn. Yet the panel’s HTML body remained unchanged, making hash-based detection more durable than blocking individual IP addresses or ports.
Researchers also identified three main operator panel variants, DarkSword Admin, Decode Dashboard, and C2 Control Panel.
A Hong Kong-based Decode Dashboard cluster exposed a five-port pattern 8000, 8881, 8882, 8888, and 9999 across three hosts.
Another panel contained Chinese language labels, while a separate C2 Control Panel displayed the name “Asia-Pacific Group” and a Telegram contact link.
A now-offline Singapore host showed how operators may combine multiple tools on one server. It exposed DarkSword panels, a Coruna administration panel, an iOS Exploit Dashboard, and a MinIO object-storage console.
Coruna is an older iOS exploit kit associated with attacks against earlier iOS versions. Researchers did not authenticate to any exposed services, so the data stored behind these panels remains unknown, Censys said.
DarkSword delivery starts when a victim visits a lure website. The staging page loads a hidden frame.html iframe, which retrieves a version-specific exploit loader.
The loader reads the iOS version from the browser user agent and selects different exploit workers depending on the device’s version.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.
