DarkSword, a powerful iPhone exploit kit whose source code was leaked online, is now being used by multiple threat actors to launch large-scale cyberattacks. The latest campaigns combine one-click Safari exploits with fake Apple ID login pages, allowing attackers to steal credentials and compromise iPhones in a single attack.
The exploit chain was originally discovered by Google Threat Intelligence Group, iVerify, and Lookout. After the complete JavaScript-based toolkit was leaked on GitHub, several unrelated attackers began reusing the same code instead of creating their own versions.
Researchers found that at least seven threat groups are now operating DarkSword infrastructure. The attackers use identical exploit files, matching code hashes, and even the same Russian-language comments found in the leaked source code, confirming they are all relying on the leaked toolkit.
One of the newest operators appears to be a Chinese-speaking threat actor managing more than 100 malicious websites across Hong Kong, Japan, the United States, and several European countries. Earlier campaigns mainly used fake AWS login pages, but researchers have now identified Apple ID phishing pages hosted on the same servers that deliver the DarkSword exploit.
How the DarkSword Campaign Works
Researchers tracked the attackers by comparing file hashes and exploit pages instead of relying only on domains or IP addresses, which change frequently. This method helped identify additional DarkSword infrastructure that traditional detection methods had missed.
According to Censys, the campaign continues to grow as attackers regularly move their infrastructure to new hosting providers and domains.
Researchers identified several key characteristics of the operation:
- Multiple DarkSword administration panels hosted in Hong Kong, Japan, and the United States.
- Chinese-language login panels running on ports such as 3000, 8443, and 8888.
- Fake Apple ID login pages hosted on the same servers as the exploit chain.
- Identical exploit files and malware modules reused across different operators.
- Infrastructure spread across multiple hosting providers to avoid easy detection.
What Happens After an iPhone Is Compromised?
One of the most dangerous changes in this campaign is the combination of Apple ID phishing pages with DarkSword’s exploit delivery. Victims believe they are signing in to a legitimate Apple account, while hidden exploit code is loaded in the background through Safari.
Security researchers say DarkSword chains multiple iOS vulnerabilities affecting WebKit, the GPU, the dynamic linker, and the kernel to gain deep access to vulnerable devices.
After a successful compromise, the malware can:
- Steal Apple Keychain passwords and saved credentials.
- Extract iCloud account information.
- Collect saved Wi-Fi passwords.
- Download files stored on the device.
- Send stolen data to attacker-controlled command-and-control (C2) servers.
Researchers also found that most DarkSword deployments use identical malware files, showing attackers are directly reusing the leaked toolkit instead of developing new versions. Although many servers are hosted in Hong Kong, the infrastructure is distributed across several internet providers, making IP-based blocking less effective.
Additional evidence, including Chinese-language control panels, references to an “Asia-Pacific Group,” and a Telegram contact, suggests the latest infrastructure is operated by a Chinese-speaking threat actor. However, researchers say there is not yet enough evidence to confidently attribute the campaign to a specific group.