Leaked DarkSword iOS exploit kit spreads to 100+ sites
DarkSword remains in use in new campaigns after its code leaked publicly. On September 4, SlowMist reported a campaign posing as a free VPS service that screened for vulnerable iPhones and reused the six-flaw DarkSword chain. The operator remains unidentified, and no official closure has been reported.
- Started
- Nov 1, 2025
- Latest activity
- Sep 4, 2026
- Attributed to
- Chinese-speaking threat actor (unnamed group)Suspected
- Where
- Hong Kong, Japan, United States
- Sectors
- Consumers
- Scale
- more than 100 lure web properties, concentrated in Hong Kong but reaching Japan, the United States, and Europe, per Censys
Current status
Searches through 2026-09-11 found no credible report or official statement after 2026-09-05; the latest confirmed update remains the SlowMist warning dated 2026-09-04.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Who is behind it
No named government agency or victim has publicly attributed this campaign.
Impact
Visiting a rigged site can trigger a one-click Safari exploit chain that installs the GHOSTBLADE implant, which is built to steal iCloud keychain passwords, Wi-Fi credentials, and other files. SlowMist also reported theft risks involving crypto wallet data and keystrokes, plus fake Apple ID or Amazon Web Services login pages that can steal account credentials.
What to do
Update iPhones to the latest iOS version now. SlowMist specifically advised updating to iOS 18.7.3 or iOS 26.3 and later. Be wary of free VPS offers and any Apple ID or AWS sign-in page reached through a link rather than typed in directly.
Timeline
-
Sep 5, 2026
BornCity published a report based on the SlowMist warning and said the targeted DarkSword flaws had already been patched by Apple. It reported no named victims, service outage, or official attribution.
Activeborncity.com -
Sep 4, 2026
SlowMist reported a DarkSword campaign disguised as a free VPS service. The site screened for Safari on iOS 18.4 through 18.6.2 and delivered a six-flaw chain that could expose wallet data and keystrokes. SlowMist did not name the operator or report a closure.
Activex.com -
Sep 1, 2026
ADEX reported that Coruna-style device and browser filtering appeared in fraudulent advertising campaigns. It said about 50 accounts showed similar behavior, but the release did not identify DarkSword victims or the GHOSTBLADE operator.
Activeprnewswire.com -
Aug 31, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Aug 10, 2026
Dark Reading reported that DarkSword and Coruna exploit variants were spreading among organized criminal groups, with 17,000 domains hosting variants. The report did not name the Chinese-speaking actor behind the tracked GHOSTBLADE campaign or report that the campaign had ended.
Activedarkreading.com -
Aug 6, 2026
SecurityOnline reported the campaign had grown to more than 100 sites delivering the GHOSTBLADE implant, urging iPhone users to update to iOS 26.
Activesecurityonline.info -
Aug 4, 2026
GBHackers reported a DarkSword server combining the exploit chain with a fake Apple ID login page to harvest credentials alongside device compromise.
Activegbhackers.com -
Aug 3, 2026
The Hacker News, citing Censys researcher Aidan Holland, reported the leaked DarkSword kit now also powers fake AWS sign-in pages alongside the Apple ID decoys, hosted mainly from Hong Kong; Censys found Chinese-language admin panel text, leftover Russian-language code comments from the leaked source, and one control panel branded with a Chinese group name and a Telegram contact link, though no formal actor name or government attribution has been made.
Activethehackernews.com -
Jul 20, 2026
Cyber Security News reported the leaked DarkSword exploit chain now spread across 180 web properties on 27 hosts, targeting unpatched iOS 18.4 through 18.7 devices.
Activecybersecuritynews.com -
Apr 1, 2026
Apple shipped an emergency patch for iOS 18 users to close the DarkSword vulnerabilities.
Activeappleinsider.com -
Nov 1, 2025
Security researchers first identified the DarkSword and Coruna iPhone exploit chains being used in targeted attacks via Snapchat-themed lures.
Activegbhackers.com
Sources
- DarkSword Server Combines iPhone Exploits With Fake Apple ID Login Page GBHackers Aug 4, 2026
- Leaked DarkSword iOS exploit spreads to 100+ sites SecurityOnline Aug 6, 2026
- DarkSword iOS Exploit Kit Spreads Across 180 Web Properties and 27 Hosts Cyber Security News Jul 20, 2026
- Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS The Hacker News Aug 3, 2026
- Coruna, DarkSword iOS Exploits Proliferate Globally Dark Reading Aug 10, 2026
- SlowMist reports iOS Safari DarkSword wallet asset theft X Sep 4, 2026
- SlowMist Team Warns of DarkSword Asset Theft via iOS Safari Coinfomania Sep 4, 2026
- DarkSword attack: Security firm warns about iPhone malware BornCity Sep 5, 2026
- ADEX Finds Coruna iOS Exploit Tactics Reused in Ad Fraud Campaigns PR Newswire Sep 1, 2026
Related reports
- DarkSword iPhone attacks steal credentials and files Aug 4, 2026
- DarkSword sites steal iPhone and iPad credentials Aug 4, 2026
- DarkSword iOS exploit kit steals data from iPhones Jul 20, 2026