DarkSword iOS exploit kit steals data from iPhones
DarkSword is a hacking toolkit built to break into iPhones after someone visits a booby-trapped website. Once it works, it can pull passwords, iCloud data, saved Wi-Fi passwords, and other sensitive files off the phone.
- Report priority
- Medium
- Targets
- iPhone+1 more
How it works
Attackers set up fake Apple sign-in pages and other lure websites that secretly load a hidden exploit chain matched to the visitor's iOS version, and if it succeeds it installs GHOSTBLADE, a data-theft tool that grabs stored passwords, cloud data, and Wi-Fi credentials before erasing its own tracks.
What to do
Check your iPhone's iOS version under Settings, General, About. You are only at risk if you are running iOS 18.4 through 18.7 and visit one of the lure sites, and most people never encounter these pages.
Install the latest available iOS update right away, since Apple's newer releases close the flaws this chain depends. If you cannot update immediately, turn on Lockdown Mode in Settings, Privacy & Security for extra protection and treat unexpected sign-in pages or unsolicited links as suspicious.
Technical details
Affected software: iPhone, GHOSTBLADE
A victim clicks a link to what looks like an Apple sign-in page or an iOS-themed site. The page silently loads a hidden exploit chain that checks the visitor's iOS version and picks matching attack code. If the exploit works, GHOSTBLADE collects keychain passwords, iCloud data, and saved Wi-Fi passwords, sends them to a server the attackers control, then deletes crash reports and log files to cover its tracks.
DarkSword is a six-vulnerability iOS exploit chain leaked via the ghh-jbDarkSword GitHub repository. Censys tracked its infrastructure by matching stable page-body hashes and a recurring five-port Decode Dashboard pattern (ports including 3000, 8443, 8888) across hosts and domains that operators rotate every few days. As of July 30, 2026, Censys counted 27 hosts and 180 web properties carrying DarkSword content, including fake AWS console pages and Apple ID credential-harvesting decoys, one of which (103.106.190.217 in Hong Kong) hosted both a phishing decoy and exploit staging content on the same server. A related Singapore host previously also ran the older Coruna iOS exploit framework.
References
- nvd.nist.gov vdb entry
- ppl-ai-file-upload.s3.amazonaws.com · DarkSword-iOS-Exploit-Kit-Spreads-Across-180-Web-Properties-and-27-Hosts.pdf Cyber Security News
- censys.com · darkswords-panel-sprawl Cyber Security News
- any.run · enterprise Cyber Security News
- thehackernews.com · hijacked-hotel-wi-fi-pushes-fake.html TheHackerNews
- infosecurity-magazine.com · teams-phishing-abused-legit Infosecurity Magazine
- infosecurity-magazine.com · logokit-phishing-real-time Infosecurity Magazine
- infosecurity-magazine.com · hugging-face-diffusers-trust Infosecurity Magazine
- infosecurity-magazine.com · jadepuffer-ai-model-ransomware Infosecurity Magazine
- neuracybintel.com · sonicwall-sma1000-zero-days-fuel-inc-ransomware-attacks-against-enterprise-vpn-infrastructure NeuraCybIntel
- securityweek.com · sonicwall-issues-urgent-sma-patch-warning-for-two-zero-day-exploits NeuraCybIntel
- securityweek.com · sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch NeuraCybIntel
- sonicwall.com · kA1VN000001nv6D0AQ NeuraCybIntel
- neuracybintel.com · critical-fastjson-rce-zero-day-under-active-exploitation-unauthenticated-attacks-hit-us-organizations NeuraCybIntel
- neuracybintel.com · microsofts-july-2026-patch-tuesday-fixes-hundreds-of-vulnerabilities-including-multiple-actively-exploited-zero-days NeuraCybIntel
- msrc.microsoft.com · update-guide NeuraCybIntel
- cisa.gov · known-exploited-vulnerabilities-catalog NeuraCybIntel
- microsoft.com · blog NeuraCybIntel
- bleepingcomputer.com · new-doublecup-clickfix-service-hides-malware-in-browser-cache-images BleepingComputer
- thehackernews.com · doublecup-uses-clickfix-and-cached-pngs.html TheHackerNews
- openwall.com · 7 Openwall oss-security
- safedep.io · joyfill-npm-blockchain-c2-supply-chain SafeDep
- safedep.io · asyncapi-generator-supply-chain-attack-miasma-rat SafeDep
- thehackernews.com · pnld-breach-exposes-uk-police-and.html TheHackerNews
- scworld.com · new-bill-proposes-lifetime-identity-protection-for-opm-data-breach-victims SC World
- scworld.com · uk-police-legal-database-breach-exposes-officer-details-increasing-phishing-risks SC World
- ncsc.gov.uk · uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign NCSC UK
- openwall.com · 6 Openwall oss-security
- thehackernews.com · google-password-manager-attacks-could.html TheHackerNews
- bleepingcomputer.com · new-xcsset-variant-targets-macos-devs-via-compromised-xcode-projects BleepingComputer