logo

TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

ID: 173b8745-8c70-5577-a825-2f31224a4c28

STIX ID: report--173b8745-8c70-5577-a825-2f31224a4c28

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-03-28

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Proofpoint and other researchers attribute a March 2026 targeted email campaign to Russian state-linked APT TA446 that used the leaked DarkSword iOS exploit kit to target iPhones. Emails spoofed the Atlantic Council and attempted to deliver GHOSTBLADE (a dataminer) and MAYBEROBOT via exploit chains and password-protected ZIPs; forensic artifacts and domain evidence (VirusTotal, urlscan) link the activity to TA446. Apple issued lock-screen warnings as the leak and public availability of DarkSword risk wider, less-skilled abuse of advanced iOS exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.