# DarkSword iOS Exploit Targets 180 Web Properties in Expansive Attack

*Published August 5, 2026*
*Source: [https://cybersecuritynews.com/darksword-ios-exploit-kit/](https://cybersecuritynews.com/darksword-ios-exploit-kit/)*

## Executive Summary

The DarkSword exploit kit has expanded to 180 web properties, targeting iOS devices to steal sensitive data. This rapid growth and evolving infrastructure present significant challenges for security teams, emphasizing the need for vigilance and timely updates.

## Article

The DarkSword exploit kit has rapidly grown from a leaked iOS exploit chain into a widespread network of malicious web operations. This campaign specifically targets iPhones running iOS versions 18.4 to 18.7, aiming to extract sensitive data from users who inadvertently visit compromised websites. The initial phase of the attack uses deceptive tactics like fake sign-in pages and iOS-themed sites that load the exploit through concealed content.

Once activated, DarkSword can bypass device protections, gaining access to crucial data such as keychain information, iCloud files, and Wi-Fi credentials. Censys researchers have been closely monitoring this evolving threat, noting the rapid turnover of servers while maintaining consistent webpage elements. According to their report, as of July 30, 2026, DarkSword was active on 27 hosts and 180 web properties, though this is a dynamic situation.

The exploit chain, which relies on a set of six vulnerabilities, was publicly leaked on the ghh-jbDarkSword GitHub repository. It employs browser-based code to escalate from a simple site visit to deeper device infiltration. The infrastructure involves fake AWS and Apple ID pages, creating a front for credential harvesting and exploit deployment.

In a notable case, a Hong Kong server hosted both an Apple-themed decoy and DarkSword content, facilitating credential theft and exploit delivery. The use of body hashes helps track this operation more effectively than domain names alone. A DarkSword Admin panel hash was identified on multiple hosts across Hong Kong, Japan, and the United States, with servers frequently rotating.

To mitigate this threat, defenders are advised to hunt for stable page-body hashes and a specific five-port pattern on Decode Dashboard hosts. Regular DarkSword exposure searches are recommended due to the quick rotation of hosts and web properties. iPhone users should promptly update their devices to the latest iOS version, and where updates are not feasible, Lockdown Mode can provide additional protection against these targeted attacks.
