TA446 Hackers Launch DarkSword Attacks On iOS Devices

Threat actor TA446 has escalated its cyber espionage operations by deploying a sophisticated exploit kit known as DarkSword to compromise iOS devices.

This marks a significant shift in the group’s tactics, as historical data shows no previous reliance on advanced exploit frameworks.

The recent campaign leverages targeted social engineering to deliver a multi-stage attack specifically tailored for Apple mobile operating systems.

The DarkSword Exploit Chain

The DarkSword framework represents a highly capable exploit kit designed to subvert modern iOS security mechanisms.

According to the URLScan analysis, the attack sequence begins with an initial redirector. This component serves as a traffic filtering mechanism, ensuring that only intended targets using vulnerable iOS devices receive the malicious payload while keeping security researchers out.

Once a valid target is confirmed, the server delivers the exploit loader, which initiates the core attack sequence.

At the heart of the DarkSword kit is a Remote Code Execution (RCE) capability. This allows the threat actors to execute arbitrary commands on the victim’s device without requiring any physical access or user interaction beyond clicking a link.

To achieve this on a heavily guarded platform like iOS, the exploit chain incorporates a PAC bypass.

Pointer Authentication Codes (PAC) are a hardware-backed security feature introduced by Apple to prevent memory corruption vulnerabilities from being easily exploited. By successfully bypassing PAC, TA446 demonstrates a high level of technical sophistication.

Infrastructure and Tactical Shifts

The deployment of DarkSword is closely tied to highly targeted phishing lures. The only confirmed use of this exploit kit by TA446 occurred during a campaign observed on March 26.

TA446 Targets iOS Devices (Source: threatinsight)
TA446 Targets iOS Devices (Source: threatinsight)

During this operation, the hackers actively spoofed the Atlantic Council, a prominent international affairs think tank. By masquerading as a trusted policy organization, the attackers aimed to trick specific victims into clicking malicious links that would trigger the DarkSword infection sequence.

According to Threat Insight research, to facilitate these attacks, TA446 relied on a network of compromised domains rather than entirely custom infrastructure.

Campaign ComponentTechnical Details
Threat ActorTA446
Target PlatformiOS Devices
Exploit KitDarkSword
Observed ComponentsRedirector, Exploit Loader, RCE, PAC Bypass
Missing ComponentsSandbox Escapes
Known LureSpoofed Atlantic Council (March 26)
Compromised Domainsmotorbeylimited[.]com, bridetvstreaming[.]org

This campaign represents a notable evolution for TA446. Before the March 26 activity involving the Atlantic Council lure, there was no indication that this threat group utilized exploits in its operations.

Their transition from standard credential harvesting to the use of an advanced iOS exploit kit like DarkSword suggests increased resources and a shift toward targeting higher-tier mobile endpoints.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories