# When an Exploit Kit Goes Rogue: How a Leaked iOS Weapon Is Now in Chinese Hands


The DarkSword exploit kit was already a serious threat when it was someone's proprietary tool. Once the source code hit public channels, it became everyone's problem.


Censys researchers this week mapped more than 100 web properties tied to a previously untracked Chinese threat actor running DarkSword against iPhones — deploying an information-stealing implant called GHOSTBLADE that tears through a victim's keychain, iCloud credentials, and Wi-Fi passwords in one sweep. The infrastructure tells a clear story: this isn't a sophisticated nation-state operation building bespoke tooling. It's opportunistic exploitation of someone else's leaked work, and that matters enormously for how defenders should respond.


## The Kit That Got Out


DarkSword surfaced in public reporting earlier this year through Google's Threat Intelligence Group, iVerify, and Lookout. At the time, it was being attributed to commercial surveillance vendors and state-sponsored actors running targeted campaigns in Saudi Arabia, Turkey, Malaysia, and Ukraine. The kit targets iOS 18.4 through 18.7 — a remarkably recent version window — and uses watering hole sites to deliver JavaScript that chains together now-patched vulnerabilities into a full compromise.


Then the source code leaked.


The moment that happened, the threat model changed. A tool that previously required either purchasing from a surveillance vendor or operating at nation-state capability level became available to anyone with enough operational know-how to run a panel. What Censys found is exactly what you'd expect to follow a leak of that kind: a new actor, running the kit largely unmodified, standing up commodity credential-harvesting infrastructure alongside it.


The tell is in the code. Researcher Aidan Holland noted that the staging-page hash matches the leaked source, and Russian-language comments from the original codebase are still present. This group didn't reimplement DarkSword. They downloaded it and pointed it at targets.


## Fake AWS Pages, Real Keychain Access


The delivery infrastructure is worth examining because it's doing two things simultaneously. Victims land on domains impersonating AWS console sign-in pages or Apple ID authentication — convincing enough phishing, designed to capture corporate and consumer credentials the old-fashioned way. But the page also silently loads an iframe that fires the DarkSword exploit chain against the visitor's iOS device.


That's belt and suspenders. Even if the exploit fails (perhaps the user is on a patched iOS version), you still get phishing credentials. And if it lands, you get GHOSTBLADE — which doesn't just log a password. It dumps the entire keychain, iCloud tokens, and saved Wi-Fi credentials, then packages everything for exfiltration to attacker-controlled endpoints.


The operator then logs into one of three admin panels — DarkSword Admin, a Decode Dashboard, or a C2 Control Panel — to retrieve the harvested data. Censys found login panels scattered across seven hosts in three countries as of July 30, with Chinese-language field labels on at least one. The infrastructure is distributed enough to resist simple takedowns but centralized enough that mapping it was possible.


## An Older Kit Lurking in the Same Stack


One of the more unsettling findings: a Singapore-based host that's now offline was running an administration panel for Coruna, a separate iOS exploit kit that predates DarkSword and targets iOS versions all the way back to 3.0 — including devices as recent as iOS 17.2.1.


The existence of both kits in the same operational cluster raises the question of whether this actor, or one related to it, is running parallel campaigns against different iOS version cohorts. Censys also noted evidence connecting a threat actor tracked as UNC6353 to both tools in campaigns targeting Ukraine. Whether that's the same group or infrastructure overlap remains open, but the correlation is notable.


## What Defenders Are Actually Dealing With


The honest assessment: if your organization's users are running iOS 18.4 through 18.7, the patched window matters most. Apple has addressed the vulnerabilities DarkSword exploits, which means the enforcement point is update compliance. Users who have auto-updates enabled and haven't ignored the prompts are not the vulnerable population here.


The harder problem is the phishing layer. Fake AWS console pages targeting enterprise users are a durable attack vector regardless of whether an exploit kit is attached. Organizations running AWS workloads should have FIDO2/passkey enforcement on AWS IAM logins — phishable MFA (TOTP, SMS) doesn't protect against this infrastructure type. AWS recently expanded passkey support, and this is exactly the scenario it was designed for.


For mobile threat detection teams, the Censys report includes specific IP ranges to track and the domain pattern for AWS impersonation subdomains worth adding to blocklists.


---


## HackWire Analysis


The DarkSword situation is a case study in what happens when offensive tooling escapes the supply chain it was built for.


Commercial surveillance vendors operate in a legal gray zone, selling to governments that promise "lawful use" while everyone in the industry knows capability diffusion is inevitable. Once an exploit kit's source code is out, the sophisticated original operator's operational security advantage collapses. The technical barrier drops from "nation-state or well-funded commercial buyer" to "threat actor with panel-administration skills." That's a meaningful expansion of the threat surface, and it's one the surveillance vendor industry has never had a credible answer to.


The parallel to think about here is Cobalt Strike — a legitimate red-team framework that became so widely cracked and redistributed that defenders spent years building detection specifically for it. DarkSword is following the same curve, just faster because the initial leak happened early in the tool's operational life.


What's underreported in most coverage of this campaign is the AWS phishing angle. The focus understandably falls on the iOS exploit, but the credential-harvesting layer is live regardless of whether exploitation succeeds. Any organization running AWS infrastructure whose users are hitting these domains is potentially losing IAM credentials to a separate collection mechanism — one that doesn't require a zero-day to work. The dual-track delivery makes this campaign more dangerous than the exploit chain alone would suggest.


Security teams should also watch the Coruna overlap. A threat actor running iOS 17.x and 18.x exploit capability simultaneously, across a distributed but mappable infrastructure, is building a target list across a wide swath of Apple's user base. The iOS 17 cohort includes users on older hardware that can't upgrade further — a population that tends to skew toward exactly the kind of targets surveillance tools are built for.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)