logo

Russia-linked APT TA446 uses DarkSword exploit to target iPhone users in phishing wave

ID: 325dd785-4c99-5571-bb10-06756de08cf7

STIX ID: report--325dd785-4c99-5571-bb10-06756de08cf7

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-03-30

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Russia-linked APT TA446 has been observed using the DarkSword iOS exploit kit in targeted spear-phishing campaigns against iPhone users, leveraging malicious links and spoofed Atlantic Council invitations to harvest credentials and collect intelligence; researchers tied observed domains, a VirusTotal loader MD5, and campaign infrastructure to the actor and noted expanded targeting across government, think tanks, NGOs, and other high-value sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.