Chinese-Speaking Operator Runs DarkSword iOS Exploit Kit Across 180 Web Properties
ID: 0e1fc05a-a282-5976-b0ff-a760f6c77e07
STIX ID: report--0e1fc05a-a282-5976-b0ff-a760f6c77e07
Feed Name: Cyber Press
Threat Score
**Executive summary:** The leaked DarkSword iOS exploit kit (targets iOS 18.4–18.7) has been actively deployed by Chinese-speaking operators across at least 180 web properties using fake AWS/Apple ID lures, rotating infrastructure, and multiple control panels to stage exploits and harvest credentials; researchers identified reusable page body hashes, an indicator IP (103.106.190.217), and cluster patterns pointing to a large, active campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
