An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.
Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit.
“The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe,” Censys researcher Aidan Holland said in an analysis published on July 31, 2026.
