DarkSword’s leaked iOS exploit chain is now powering a fast‑moving server cluster that marries one‑click Safari exploitation with a convincing fake Apple ID login page, putting millions of iPhone users at risk of seamless device compromise and credential theft.
Originally disclosed by Google Threat Intelligence Group, iVerify, and Lookout, the kit was later leaked to GitHub (ghh‑jb/DarkSword), where its complete JavaScript‑based chain including PAC bypass and sandbox escape became freely available.
The same codebase now runs in the hands of at least seven, and likely eight, unrelated operators, all reusing the leaked chain rather than re‑implementing it, as evidenced by shared staging‑page hashes and Russian‑language code comments carried verbatim into live deployments.
One of the latest operators is a Chinese‑speaking actor controlling more than a hundred web properties spread across Hong Kong, Japan, the United States, and parts of Europe, with most lures fronted by fake AWS sign‑in pages and, in the newest pattern, an Apple ID login page co‑hosted on infrastructure that also serves DarkSword.
None of the analysis required source access beyond the leak itself: investigators pivoted entirely on live infrastructure, hashing panel bodies and exploit files and watching which artifacts stayed fixed as hosts and domains churned week to week.
Censys already fingerprints DarkSword and exposes it via the “DarkSword” ARC threat label, which currently spans 27 hosts and 180 web properties as of 30 July 2026, though that count moves constantly as operators stand up and abandon domains.
Because labels only cover what has already been fingerprinted, researchers went further, using exact SHA‑256 body hashes on operator‑facing panels and the exploit staging page to track infrastructure the label missed.
The DarkSword Admin login panel now resolves to seven hosts across Hong Kong, Japan, and the United States, answering on ports :3000, :8443, and :8888, with Chinese‑language field labels for username and password.
This panel hash has stayed constant while the underlying hosts turn over in under seven days, making body‑hash equality a more reliable indicator than domain or port for defenders hunting the cluster.
A parallel hash on the “Decode Dashboard 登录” panel isolates a concentrated pocket on PCCW22‑HK (AS135357), where three hosts expose a five‑port C2 fingerprint, while a third hash tags the “C2 Control Panel” now tied to an Apple‑themed lure.
Underneath all of them, a separate hash, 50582f8d…, marks the exploit‑chain staging page deployed across all 27 labeled hosts, anchoring detection for the actual delivery tier.
The most dangerous evolution in this operator’s playbook is at 103.106.190[.]217, where an Apple‑branded credential‑harvesting page styled as “iCloud – Apple” and presenting an Apple ID sign‑in prompt with Chinese‑language labels is co‑hosted on the same IP and ports that serve DarkSword’s staging page.
Censys Researchers said that, DarkSword is a commercial, full‑chain iOS exploit kit chaining six vulnerabilities across WebKit, GPU, dynamic linker, and kernel to compromise iPhones running iOS 18.4 through 18.7 fully.
Previous lures in the DarkSword ecosystem impersonated AWS consoles, generic Chinese web services, or media portals, keeping credential theft and exploit delivery on separate infrastructure; this is the first time Apple‑branded phishing is fused directly into exploit staging.
From a victim’s point of view, the flow is seamless: they land on what looks like a legitimate Apple ID login or cloud console, the web root quietly returns the known 50582f8d… staging page with a hidden frame.html iframe.
DarkSword Server Combines iPhone
The iframe loads rce_loader.js and per‑version RCE workers that chain six DarkSword vulnerabilities to gain kernel r/w, escape the sandbox, and deploy GHOSTBLADE modules.
The implant then dumps keychain, iCloud, and Wi‑Fi credentials, exfiltrates files to C2 collector endpoints, presents the loot through DarkSword Admin or C2 Control Panel logins.
A file‑level hash study across 100 DarkSword‑serving web properties makes the leak lineage explicit. Core payload modules like ghostblade.js, keychain_copier.js, wifi_password_securityd.js, icloud_dumper.js, and file_downloader.js are byte‑for‑byte identical everywhere.

In contrast, version‑dispatch and loader components like frame.html and rce_loader.js show up to 10 and 14 distinct hashes, respectively, because they must branch on iOS version and device profile to pull the right exploit worker builds.
At the composite level, a chain_fingerprint across the full file set yields 24 distinct deployment images, but two fingerprints alone account for over 60 percent of observed properties, with the rest forming a long tail plus a handful of pure lure fronts that never served core‑chain files at scan time.
Nearly half of surveyed domains expose no core DarkSword files at all, while a small cluster of properties carry dozens of novel files beyond any cataloged hash, suggesting at least one heavily modified variant the community has yet to fully analyze.
Censys telemetry reveals that the operator favors Hong Kong hosting but deliberately spreads across a dozen carriers from NetLab Global and PCCW to GNET and cognetcloud avoiding dependence on any single AS and making IP‑based blocking brittle.
A now‑dark Singapore host surfaced a rare constellation of three DarkSword panels, a Coruna management console, and an unauthenticated MinIO object‑storage console on one IP, echoing Google’s prior tracking of UNC6353’s migration from Coruna to DarkSword yet showing independent operators now blending both kits on shared infrastructure.
Chinese‑language panel titles, zh‑CN markup, the group name “Asia‑Pacific Group” (亚太集团) on the C2 Control Panel, and a visible Telegram contact link (t[.]me/YATA0000) collectively point to a Chinese‑speaking operator but stop short of firm attribution.
An exposed .ssh/authorized_keys file on a Frankfurt host, carrying the comment jkcing@apt alongside cached ffuf and Go telemetry data, provides a rare glimpse of the operator’s own recon tooling and a probable handle, though this, too, remains a lead rather than a confirmed identity.
Why use the 2026 Agentic SOC Buyer’s Guide? 8 Best Platforms Compared – Download the 2026 Buyer’s Guide

