A Chinese-speaking threat actor has deployed more than 100 web properties targeting Apple iOS devices using a publicly leaked exploit kit, according to a report from attack surface management platform Censys published on July 31, 2026. Most of the identified sites pose as fake Amazon Web Services sign-in pages on domains that also host the DarkSword exploit toolkit. The hosting infrastructure concentrates in Hong Kong but extends into Japan, the United States, and Europe, researcher Aidan Holland found.

DarkSword is a full-chain exploit kit that targets iOS versions 18.4 through 18.7, originally discovered earlier this year by Google Threat Intelligence Group, iVerify, and Lookout. The kit has been used by commercial surveillance vendors and suspected state-sponsored actors in campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025. Censys identified seven hosts running a login page for "DarkSword Admin" across three countries as of July 30, 2026. The investigation also uncovered a Singapore-based host operating three distinct exploit-panel front ends and a Hong Kong host bundling an Apple ID credential-harvesting decoy. One login panel served on IP address 38.22.89.117:8888 contains Chinese-language field labels for username, password, and log in.

The attack begins when victims reach one of the operator's domains—an AWS-console impersonation subdomain or an Apple ID sign-in page—which loads a malicious iframe element that fires the DarkSword chain and deploys GHOSTBLADE malware modules. According to Holland's analysis, "This cluster runs the leaked kit rather than a reimplementation, and the evidence is a shared staging-page hash plus Russian-language code comments carried over from the leaked source." Upon successful exploitation, the implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules and begins a file-exfiltration sweep. The stolen data is then packaged and transmitted to attacker-controlled endpoints, where the operator logs in to one of three panels—DarkSword Admin, Decode Dashboard, or C2 Control Panel—to extract the information.

The campaign illustrates how public leaks of sophisticated exploit code lower the barrier for additional threat actors to launch attacks. The Singaporean host, now inactive, also hosted an administration panel for Coruna, another iOS exploit kit that targets versions 3.0 through 17.2.1 and predates DarkSword. Censys discovered an open directory listing in Frankfurt that exposes the operator's tooling, including an SSH key comment "jkcing@apt," a web-content fuzzer, and references to a previously undocumented malware family called Thorn C2. The C2 Control Panel login features a distinctive build with a near-black background, red accent, animated particle-canvas effect, and renders a group name directly on the page—亚太集团, or "Asia-Pacific Group"—along with a visible Telegram contact link, marking the first direct contact channel recovered for this operator.