TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
ID: 173b8745-8c70-5577-a825-2f31224a4c28
STIX ID: report--173b8745-8c70-5577-a825-2f31224a4c28
Feed Name: The Hacker News
Proofpoint and other researchers attribute a March 2026 targeted email campaign to Russian state-linked APT TA446 that used the leaked DarkSword iOS exploit kit to target iPhones. Emails spoofed the Atlantic Council and attempted to deliver GHOSTBLADE (a dataminer) and MAYBEROBOT via exploit chains and password-protected ZIPs; forensic artifacts and domain evidence (VirusTotal, urlscan) link the activity to TA446. Apple issued lock-screen warnings as the leak and public availability of DarkSword risk wider, less-skilled abuse of advanced iOS exploits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
