TA446 Uses DarkSword Exploit Kit to Target iPhone Users
ID: 635d2305-bcb6-593c-b0f1-6fc787086be2
STIX ID: report--635d2305-bcb6-593c-b0f1-6fc787086be2
Feed Name: GBHackers
A Russia-linked espionage group TA446 has begun using the leaked DarkSword iOS exploit kit in a spear‑phishing campaign spoofing Atlantic Council event invites to target government, think-tank, higher-education, financial, and legal organizations. Researchers observed TA446-controlled and compromised redirector domains (escofiringbijou.com, motorbeylimited.com, bridetvstreaming.org) serving the DarkSword redirector, loader, RCE, and PAC bypass stages; Apple has pushed updates and defenders are advised to patch devices, block known infrastructure, and monitor for Safari exploit-chain activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
