TA446 Hackers Deploying DarkSword Exploit Kit to Attack iOS Users
ID: 528a6a8d-1e13-52d8-9b3c-2b125ccd32d1
STIX ID: report--528a6a8d-1e13-52d8-9b3c-2b125ccd32d1
Feed Name: cybersecurityNews.com
Threat actors identified as TA446 are employing a newly observed iOS-focused exploit kit called DarkSword in broad spoofed email campaigns (including impersonation of the Atlantic Council) to perform credential harvesting and intelligence collection; DarkSword is modular (redirector, exploit loader, RCE, PAC bypass), infrastructure and indicators (domains and an MD5-hashed loader) were observed, and defenders are advised to block malicious domains, monitor proxy configuration changes, avoid clicking unexpected links, and keep iOS devices updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
