logo

Chinese-Speaking Operator Runs DarkSword iOS Exploit Kit Across 180 Web Properties

ID: 0e1fc05a-a282-5976-b0ff-a760f6c77e07

STIX ID: report--0e1fc05a-a282-5976-b0ff-a760f6c77e07

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Varshini

...
...

**Executive summary:** The leaked DarkSword iOS exploit kit (targets iOS 18.4–18.7) has been actively deployed by Chinese-speaking operators across at least 180 web properties using fake AWS/Apple ID lures, rotating infrastructure, and multiple control panels to stage exploits and harvest credentials; researchers identified reusable page body hashes, an indicator IP (103.106.190.217), and cluster patterns pointing to a large, active campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.