DarkSword Exploit Exposes iOS Vulnerabilities
The Rise of a New Threat
Six iOS vulnerabilities accidentally leaked on GitHub rapidly evolved into a formidable weapon. Now, at least seven independent threat groups actively utilize this exploit. This threat involves the commercial DarkSword exploit chain. It specifically targets iOS versions 18.4 through 18.7.
Recently, Censys mapped the infrastructure supporting this malicious network. Consequently, researchers discovered a much broader operational scale than previously assumed.
Tracking the DarkSword Infrastructure
Interestingly, domains and IP addresses did not play the central role in this investigation. Instead, experts relied on a static fingerprint from the “DarkSword Admin” login page. By late July, analysts located this specific SHA-256 hash across seven distinct servers. Furthermore, these machines operated across Hong Kong, Japan, and the United States on various ports.
Elusive Servers and Consistent Code
These servers exhibit remarkably short lifespans. For example, five out of the seven detected servers did not even exist a week prior. Meanwhile, the operators rotate their domains with even greater frequency. However, the login panel content remains completely static. Therefore, this consistency provided the most reliable method to track the entire cluster.
Source code analysis of one hundred web resources revealed a startling fact. A singular, unified toolkit drives these attacks rather than numerous independent copies. Specifically, modules designed to steal iCloud keychain data matched perfectly byte for byte.
Only the files responsible for selecting the appropriate iOS exploit displayed variations. Analysts documented up to fourteen distinct versions of these selector files. Curiously, nearly half of the examined resources lacked a functional exploit chain. They merely served as decoy pages without any active payload.
Operational Mistakes and Exposures
One particular server in Singapore stood out significantly. It simultaneously hosted control panels for both DarkSword and an older iOS exploit named Coruna. Additionally, it exposed an unprotected MinIO storage console. Previously, these cluster operators never mixed different malicious projects on a single machine. Fortunately, administrators deactivated this server before the report publication.
Phishing Tactics and Uncovered Identities
On a Hong Kong server, investigators found a control panel merged with a counterfeit Apple ID login page. Previously, these fake pages impersonated AWS or regional Asian services. They never directly spoofed Apple itself before this discovery.
Furthermore, an openly accessible directory on a Frankfurt server exposed the operator’s personal working files. This treasure trove included command histories and an SSH access key. It also revealed the username, machine name, and cache data from a web directory brute-forcing tool.
Analysts also discovered an active Telegram link on one server’s login panel. Consequently, this represents the first direct communication channel officially linked to this cluster. Multiple characteristics strongly suggest the involvement of a Chinese-speaking operator. These clues include Chinese interface text and the specific group name displayed on the login pages.
Defensive Recommendations for Organizations
Organizations must adopt new strategies to mitigate these severe risks. Security teams should not track infrastructure using ephemeral domains. Instead, they must hunt for the static fingerprints of the login pages. Moreover, monitoring for characteristic open port configurations provides much better visibility. Regular external infrastructure audits against these specific indicators remain absolutely essential.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.