Active Medium impact Ransomware Checked 6h ago

Leaked DarkSword iOS exploit kit spreads to 100+ sites

DarkSword remains in use in new campaigns after its code leaked publicly. On September 4, SlowMist reported a campaign posing as a free VPS service that screened for vulnerable iPhones and reused the six-flaw DarkSword chain. The operator remains unidentified, and no official closure has been reported.

Started
Nov 1, 2025
Latest activity
Sep 4, 2026
Attributed to
Chinese-speaking threat actor (unnamed group)Suspected
Where
Hong Kong, Japan, United States
Sectors
Consumers
Scale
more than 100 lure web properties, concentrated in Hong Kong but reaching Japan, the United States, and Europe, per Censys

Current status

Searches through 2026-09-11 found no credible report or official statement after 2026-09-05; the latest confirmed update remains the SlowMist warning dated 2026-09-04.

Active: Confirmed and still going. Attacker activity or disruption is continuing.

Who is behind it

No named government agency or victim has publicly attributed this campaign.

Impact

Visiting a rigged site can trigger a one-click Safari exploit chain that installs the GHOSTBLADE implant, which is built to steal iCloud keychain passwords, Wi-Fi credentials, and other files. SlowMist also reported theft risks involving crypto wallet data and keystrokes, plus fake Apple ID or Amazon Web Services login pages that can steal account credentials.

What to do

Update iPhones to the latest iOS version now. SlowMist specifically advised updating to iOS 18.7.3 or iOS 26.3 and later. Be wary of free VPS offers and any Apple ID or AWS sign-in page reached through a link rather than typed in directly.

Timeline

  1. Sep 5, 2026

    BornCity published a report based on the SlowMist warning and said the targeted DarkSword flaws had already been patched by Apple. It reported no named victims, service outage, or official attribution.

    Activeborncity.com
  2. Sep 4, 2026

    SlowMist reported a DarkSword campaign disguised as a free VPS service. The site screened for Safari on iOS 18.4 through 18.6.2 and delivered a six-flaw chain that could expose wallet data and keystrokes. SlowMist did not name the operator or report a closure.

    Activex.com
  3. Sep 1, 2026

    ADEX reported that Coruna-style device and browser filtering appeared in fraudulent advertising campaigns. It said about 50 accounts showed similar behavior, but the release did not identify DarkSword victims or the GHOSTBLADE operator.

    Activeprnewswire.com
  4. Aug 31, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  5. Aug 10, 2026

    Dark Reading reported that DarkSword and Coruna exploit variants were spreading among organized criminal groups, with 17,000 domains hosting variants. The report did not name the Chinese-speaking actor behind the tracked GHOSTBLADE campaign or report that the campaign had ended.

    Activedarkreading.com
  6. Aug 6, 2026

    SecurityOnline reported the campaign had grown to more than 100 sites delivering the GHOSTBLADE implant, urging iPhone users to update to iOS 26.

    Activesecurityonline.info
  7. Aug 4, 2026

    GBHackers reported a DarkSword server combining the exploit chain with a fake Apple ID login page to harvest credentials alongside device compromise.

    Activegbhackers.com
  8. Aug 3, 2026

    The Hacker News, citing Censys researcher Aidan Holland, reported the leaked DarkSword kit now also powers fake AWS sign-in pages alongside the Apple ID decoys, hosted mainly from Hong Kong; Censys found Chinese-language admin panel text, leftover Russian-language code comments from the leaked source, and one control panel branded with a Chinese group name and a Telegram contact link, though no formal actor name or government attribution has been made.

    Activethehackernews.com
  9. Jul 20, 2026

    Cyber Security News reported the leaked DarkSword exploit chain now spread across 180 web properties on 27 hosts, targeting unpatched iOS 18.4 through 18.7 devices.

    Activecybersecuritynews.com
  10. Apr 1, 2026

    Apple shipped an emergency patch for iOS 18 users to close the DarkSword vulnerabilities.

    Activeappleinsider.com
  11. Nov 1, 2025

    Security researchers first identified the DarkSword and Coruna iPhone exploit chains being used in targeted attacks via Snapchat-themed lures.

    Activegbhackers.com

Sources

Related reports