logo

TA446 Hackers Deploying DarkSword Exploit Kit to Attack iOS Users

ID: 528a6a8d-1e13-52d8-9b3c-2b125ccd32d1

STIX ID: report--528a6a8d-1e13-52d8-9b3c-2b125ccd32d1

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Threat actors identified as TA446 are employing a newly observed iOS-focused exploit kit called DarkSword in broad spoofed email campaigns (including impersonation of the Atlantic Council) to perform credential harvesting and intelligence collection; DarkSword is modular (redirector, exploit loader, RCE, PAC bypass), infrastructure and indicators (domains and an MD5-hashed loader) were observed, and defenders are advised to block malicious domains, monitor proxy configuration changes, avoid clicking unexpected links, and keep iOS devices updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.