Threat actor TA446 has escalated its cyber espionage operations by deploying a sophisticated exploit kit known as DarkSword to compromise iOS devices.
This marks a significant shift in the group’s tactics, as historical data shows no previous reliance on advanced exploit frameworks.
The recent campaign leverages targeted social engineering to deliver a multi-stage attack specifically tailored for Apple mobile operating systems.
The DarkSword Exploit Chain
The DarkSword framework represents a highly capable exploit kit designed to subvert modern iOS security mechanisms.
According to the URLScan analysis, the attack sequence begins with an initial redirector. This component serves as a traffic filtering mechanism, ensuring that only intended targets using vulnerable iOS devices receive the malicious payload while keeping security researchers out.
Once a valid target is confirmed, the server delivers the exploit loader, which initiates the core attack sequence.
At the heart of the DarkSword kit is a Remote Code Execution (RCE) capability. This allows the threat actors to execute arbitrary commands on the victim’s device without requiring any physical access or user interaction beyond clicking a link.
To achieve this on a heavily guarded platform like iOS, the exploit chain incorporates a PAC bypass.
Pointer Authentication Codes (PAC) are a hardware-backed security feature introduced by Apple to prevent memory corruption vulnerabilities from being easily exploited. By successfully bypassing PAC, TA446 demonstrates a high level of technical sophistication.
Infrastructure and Tactical Shifts
The deployment of DarkSword is closely tied to highly targeted phishing lures. The only confirmed use of this exploit kit by TA446 occurred during a campaign observed on March 26.

During this operation, the hackers actively spoofed the Atlantic Council, a prominent international affairs think tank. By masquerading as a trusted policy organization, the attackers aimed to trick specific victims into clicking malicious links that would trigger the DarkSword infection sequence.
According to Threat Insight research, to facilitate these attacks, TA446 relied on a network of compromised domains rather than entirely custom infrastructure.
| Campaign Component | Technical Details |
|---|---|
| Threat Actor | TA446 |
| Target Platform | iOS Devices |
| Exploit Kit | DarkSword |
| Observed Components | Redirector, Exploit Loader, RCE, PAC Bypass |
| Missing Components | Sandbox Escapes |
| Known Lure | Spoofed Atlantic Council (March 26) |
| Compromised Domains | motorbeylimited[.]com, bridetvstreaming[.]org |
This campaign represents a notable evolution for TA446. Before the March 26 activity involving the Atlantic Council lure, there was no indication that this threat group utilized exploits in its operations.
Their transition from standard credential harvesting to the use of an advanced iOS exploit kit like DarkSword suggests increased resources and a shift toward targeting higher-tier mobile endpoints.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.