Leaked DarkSword Exploit Kit Fuels iOS Campaign Targeting Saudi Arabia

A leaked iOS exploit kit called DarkSword is now deploying GHOSTBLADE stealer malware across Saudi Arabia, Turkey, Malaysia and Ukraine, researchers say.

Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA Region5 min read
A smartphone resting on a desk beside a laptop in an office setting, representing mobile device security risk

A smartphone resting on a desk beside a laptop in an office setting, representing mobile device security risk

Mobile threat intelligence reports usually describe theoretical risk. This one names specific countries, specific iOS versions, and a specific piece of malware now confirmed to be spreading well beyond its original operator, and that combination is exactly why it belongs in this week's gulf cyber security news coverage.

Censys, an attack surface management platform, has identified an unknown Chinese-speaking threat actor running a campaign against Apple iOS devices, built around a publicly leaked version of an exploit kit called DarkSword. The operation runs more than one hundred web properties, most of them fake Amazon Web Services sign-in pages and fake Apple ID login pages, hosted on infrastructure that also serves the exploit toolkit itself. Censys researcher Aidan Holland traced the hosting concentration to Hong Kong, with additional infrastructure reaching into Japan, the United States and Europe.

DarkSword itself is not new. It was first discovered and detailed back in March by Google's Threat Intelligence Group, alongside mobile security researchers iVerify and Lookout, as a full chain exploit kit believed to have been used by commercial surveillance vendors and suspected state sponsored actors. It specifically targets iOS versions 18.4 through 18.7, and its attack flow begins with watering hole techniques that trigger now patched vulnerabilities in Apple's mobile operating system to execute JavaScript, ultimately deploying an information stealing malware called GHOSTBLADE.

The detail that matters most for readers following mena cyber security news is where this kit has actually been used. DarkSword has been deployed in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia and Ukraine since at least November 2025. This is not a hypothetical regional risk. It is a documented pattern of use against a specific set of countries, one of which is Saudi Arabia, over a period of nine months and counting, and it has now escalated further following the public leak of the kit's source code.

That leak is the pivot point in this story. Commercial surveillance tools and state sponsored exploit kits typically stay tightly controlled, licensed to specific government or law enforcement customers who pay heavily for access and operational support. Once DarkSword's source code leaked publicly on GitHub, that control disappeared. Other threat actors, including one tracked as TA446, moved quickly to deploy the leaked kit in their own campaigns. The Chinese-speaking operator Censys is now tracking is a further example of that same pattern, running the leaked kit rather than a reimplementation, evidenced by a shared staging page hash and Russian language code comments carried over directly from the leaked source.

Once a victim reaches one of the operator's domains, either an AWS console impersonation subdomain or a fake Apple ID sign-in page, a malicious iframe loads JavaScript that fires the DarkSword exploit chain and deploys GHOSTBLADE's modules. On successful exploitation, the implant delivers keychain, iCloud and Wi-Fi credential dumping modules, then begins a file exfiltration sweep, packaging harvested data for transmission to attacker controlled endpoints. The stolen data is then retrieved through one of three administration panels Censys identified: DarkSword Admin, Decode Dashboard, or C2 Control Panel.

Censys's investigation went further than simply mapping infrastructure. One panel, hosted in Hong Kong, displays a distinctive dark interface with a group name rendered directly on the page reading Asia-Pacific Group, alongside a visible Telegram contact link, the first direct contact channel researchers have recovered for this operator. A separate open directory discovered in Frankfurt exposed additional operator tooling, including an SSH key comment and references to a previously undocumented malware family called Thorn C2. Researchers also found overlap with a second, older iOS exploit kit called Coruna, and noted that a threat actor tracked as UNC6353 appears to have used both kits in attacks against Ukrainian targets.

For enterprises and government entities operating in Saudi Arabia, this is a reminder that mobile device security cannot be treated as a secondary concern behind traditional network and endpoint protection. Organisations that have already begun tightening identity and access controls should extend that same scrutiny to mobile fleets specifically, since credential and keychain theft sit at the centre of this campaign. iOS has historically been viewed as a comparatively hardened platform, and GHOSTBLADE's ability to dump iCloud and Wi-Fi credentials directly undermines any assumption that mobile devices sit outside a realistic threat model, particularly for executives, government officials or anyone handling sensitive information.

Regional compliance frameworks are increasingly built around exactly this kind of risk. Saudi Arabia's own NCA cybersecurity framework already expects organisations to account for endpoint and mobile exposure as part of broader risk governance, and the credential harvesting at the heart of this campaign overlaps directly with obligations set out in frameworks such as the UAE PDPL compliance checklist for organisations handling personal data across borders.

Security teams should treat fake cloud provider login pages, including convincing AWS and Apple ID sign-in clones, as an active social engineering vector right now, not a hypothetical one. Detection tooling capable of flagging anomalous iCloud and keychain access, the kind evaluated in our recent look at SIEM solutions across the GCC, combined with mobile threat detection tuned specifically for iOS exploitation attempts, is a reasonable and current response to a documented, ongoing campaign. Organisations weighing third party security validation may also find it useful to revisit our guide to penetration testing requirements for regulatory vendors across the GCC, since mobile attack surfaces are increasingly falling inside the scope of those assessments, alongside broader cyber threat intelligence programmes built to track exactly this kind of tooling reuse.

As leaked, previously exclusive tooling continues spreading to new operators, staying current with mena cyber news on exactly which kits are circulating, and which countries they are being aimed at, is no longer optional context for regional security teams. It is operational intelligence, and DarkSword's trajectory since March shows how quickly a single leak can turn one operator's exclusive tool into an entire ecosystem's shared weapon.

Omar Al-Hakeem

Senior Cyber Threat Analyst | MENA Region

Omar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.

Intelligence Focus Areas

Mobile threat intelligenceSaudi Arabia cyber securityGCC endpoint protection