DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster
ID: 2a2fa6c5-a8fc-594d-a8fb-6089cef8f65c
STIX ID: report--2a2fa6c5-a8fc-594d-a8fb-6089cef8f65c
Feed Name: Censys Blog
DarkSword is a leaked commercial iOS exploit chain (six chained vulnerabilities targeting iOS 18.4–18.7) actively deployed by multiple operators; investigators observed identical exploit and payload files across many web properties, wide infrastructure churn across ASNs and countries (notably Hong Kong), operator-facing panels with stable body-hash fingerprints, and active exfiltration modules (keychain, iCloud, Wi‑Fi). The report provides host/IP and body/file hashes, behavioral indicators (open directories, SSH key comment, Telegram contact), and recommended defender actions: hunt on panel/staging body hashes and HTTP-body fingerprints rather than domain lists due to rapid churn.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
