DarkSword iOS Exploit Kit Spreads Across 180 Web Properties and 27 Hosts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

DarkSword has expanded from a leaked iOS exploit chain into a broad and fast-changing network of malicious web infrastructure.

The campaign targets iPhones running iOS 18.4 through 18.7 and is designed to steal highly sensitive data after a victim visits a lure site.

The attack begins with fake sign-in pages, iOS-themed sites, and compromised web properties that load the exploit chain through hidden content.

Once triggered, DarkSword can bypass protections, access device data, and deliver GHOSTBLADE modules built to collect keychain, iCloud, Wi-Fi, and other files.

Researchers at Censys identified the latest infrastructure growth while tracking stable web-page fingerprints across rapidly changing hosts and domains.

Their findings show that the operators are replacing servers in days while retaining recognizable panel and staging-page content.

Censys said in a report shared with Cyber Security News (CSN) that the scale makes this campaign especially concerning.

Censys observed 27 hosts and 180 web properties carrying the DarkSword label as of July 30, 2026, though the researchers stressed that this represents a changing snapshot rather than a fixed list.

DarkSword iOS Exploit Kit

DarkSword is a six-vulnerability exploit chain publicly leaked through the ghh-jbDarkSword GitHub repository.

DarkSword Admin login panel (Source – Censys)

It uses browser-based code to move from a victim’s visit to deeper device access, following the same broad threat model described in previous DarkSword exploit coverage of attacks against high-value iPhone users.

The infrastructure included fake AWS console pages, Apple ID credential-harvesting pages, and other disposable lure fronts.

One Hong Kong server, 103.106.190.217, hosted both an Apple-themed sign-in decoy and DarkSword staging content, combining credential theft and exploit delivery on the same system.

The body hashes offer a stronger way to follow the operation than domains alone. A DarkSword Admin panel hash appeared on seven hosts in Hong Kong, Japan, and the United States, even as five of those hosts changed within a week.

The actors also exposed several operator panels on unusual ports, including 3000, 8443, and 8888.

Three Hong Kong Decode Dashboard hosts shared a five-port pattern, while one Singapore host previously ran DarkSword alongside Coruna, an older iOS exploit framework discussed in earlier Coruna exploit analysis.

Lures, Data Theft, and Defense

A victim who reaches a malicious page is served a staging page that silently loads a hidden frame and selects exploit code based on the iOS version.

If the attack works, GHOSTBLADE components collect credentials, cloud data, saved Wi-Fi passwords, and files before sending the data to attacker-controlled collection endpoints.

The DarkSword operator attack flow (Source – Censys)

The operators also try to remove signs of compromise by deleting crash reports and RemoteLog.log before exiting.

Their Apple ID decoy is particularly notable because it could capture credentials directly, a tactic that mirrors the social-engineering risk seen in Apple ID phishing campaigns.

For defenders, the report recommends hunting stable page-body hashes and the full five-port Decode Dashboard pattern instead of relying only on domain or IP blocklists.

The ‘iCloud – Apple’ credential-harvesting page (Source – Censys)

Teams should rerun DarkSword exposure searches at least weekly because the hosts and web properties rotate quickly.

Where an immediate update is not possible, Lockdown Mode can add protection against highly targeted browser-based attacks, while unexpected sign-in pages and unsolicited links should be treated as suspicious.

Indicators of Compromise (IoCs):-

Type Indicator Description
SHA-256 body hash 3c37835766ca615f5eb0e766b4000b43e896a420d575f02e1e160be5711e0782 Decode Dashboard panel
SHA-256 body hash 46a0bd09f145ab909e5bf45fafe906f452f06971bd227653f0c52af8e22da89e DarkSword Admin panel
SHA-256 body hash 273df85db2d449bbf32a44848877b07b417667eb96481ce37e46bf04dd6cc222 C2 Control Panel
SHA-256 body hash 50582f8d52e49f549615ec7cd68629b9f939a0cfc5c5408f324b2f1cff070e99 Exploit-chain staging page
SHA-256 body hash d37b6198034995b8642f78706e197b3ead3cdf125d7f9cf47a60dc7f9b8ef789 iCloud Apple credential-harvesting decoy
SHA-256 body hash 0a60f8ba0c0fa86f469c973cccc853f5d71a7ae8f2a9e057d6c7735d2c28070a Thorn C2 panel, co-resident and not confirmed as DarkSword
IP:Port 38.22.89.117:8888 DarkSword Admin panel
IP:Port 103.97.128.67:8888 DarkSword Admin panel
IP:Port 162.4.136.30:8888 DarkSword Admin panel
IP:Port 223.26.63.56:8888 DarkSword Admin panel
IP:Port 151.243.126.191:8888 DarkSword Admin panel
IP:Port 151.243.126.191:8443 Group page on DarkSword Admin host
IP:Port 107.175.49.181:3000 DarkSword Admin panel
IP:Port 103.238.129.112:3000 DarkSword Admin panel
IP address 103.226.155.200 Decode Dashboard host with five-port signature
IP address 103.226.155.201 Decode Dashboard host with five-port signature
IP address 202.8.120.249 Decode Dashboard host with five-port signature
IP address 103.106.190.217 C2 Control Panel and Apple ID decoy host
IP:Port 93.152.221.37:9999 Open directory exposing operator tooling
IP:Port 93.152.221.37:443 Thorn C2 panel
IP address 64.90.10.72 DarkSword staging lure front
IP address 38.76.185.209 Staging front with Xianyu-themed decoy
IP address 45.207.210.78 DarkSword staging lure front
IP address 45.197.237.210 DarkSword staging lure front
IP address 45.197.237.216 DarkSword staging lure front
IP address 156.224.25.7 DarkSword staging lure front
IP address 156.252.63.109 DarkSword staging lure front
IP address 43.255.156.130 DarkSword staging lure front
IP address 192.210.239.136 DarkSword staging lure front
IP address 177.3.41.61 DarkSword staging lure front
IP address 43.98.179.15 DarkSword staging lure front
IP address 136.244.95.4 DarkSword staging lure front
IP address 80.66.72.87 DarkSword staging lure front
IP address 2.26.22.89 DarkSword staging lure front
IP address 75.119.146.156 DarkSword staging lure front
Historical IP address 38.181.52.95 Singapore Coruna and DarkSword infrastructure, no longer active
Historical IP address 1.32.228.62 Previously documented DarkSword infrastructure
Historical IP address 202.162.109.71 Previously documented DarkSword infrastructure
Historical IP address 130.94.30.48 Previously documented DarkSword infrastructure
Historical IP address 38.12.47.193 Previously documented DarkSword infrastructure
Domain se006.vip Certificate SAN correlation to Decode Dashboard cluster
Domain ng28jt.xyz TLS certificate name on C2 Control Panel host
Domain jkonnet.buzz Base domain used in fake AWS console cluster
Domain tronide.cc Base domain hosting mixed administration subdomains
Domain myymk.cc Base domain hosting delivery subdomains
Domain ytl99.vip Base domain hosting delivery subdomains
Domain dcgfun.top Base domain hosting delivery subdomains
Historical domain static.cdncounter.net Former loader-delivery domain, now parked
Historical domain df45gdf48g.com Previously documented DarkSword domain
URL hxxps://t[.]me/YATA0000 Telegram contact link shown on C2 Control Panel
Network signature 8000, 8881, 8882, 8888, 9999 Decode Dashboard five-port pattern, scoped to Hong Kong AS135357
Panel title DarkSword Admin Operator panel title
Panel title Decode Dashboard Operator panel title
Panel title C2 Control Panel Operator panel title
Panel title Coruna Co-resident exploit-kit panel title
Panel title DarkSword DarkSword management panel title
Panel title iOS Exploit Dashboard Operator console title
File name index.html Staging-page file
File name ghostblade.js GHOSTBLADE payload module
File name keychaincopier.js Keychain collection module
File name wifipasswordsecurityd.js Wi-Fi credential-related module
File name iclouddumper.js iCloud data collection module
File name filedownloader.js File collection module
File name loader.js Exploit loader
File name wifipassworddump.js Wi-Fi password collection module
File name rcemodule.js Remote code execution module
File name rcemodule18.6.js iOS 18.6 remote code execution module
File name rceworker.js Remote code execution worker
File name rceworker18.6.js iOS 18.6 remote code execution worker
File name rceworker18.4.js iOS 18.4 remote code execution worker
File name rceloader.js Version-dispatch exploit loader
File name frame.html Hidden iframe loader
File name sbx1main.js Sandbox escape module
File name sbx0main18.4.js iOS 18.4 sandbox escape module
File name pemain.js Privilege escalation module
File artifact RemoteLog.log Log file deleted during anti-forensics cleanup
File artifact .bashhistory Exposed operator directory artifact
File artifact .ssh/authorized_keys Exposed SSH authorization file
Behavioral artifact jkcingapt SSH key comment recovered from exposed directory
Tool artifact .config/ffuf Cached ffuf configuration directory

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN