Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagephishing-campaign-intelligenceproof-of-concept-releaseendpoint-software-vulnerability

TA446 Uses DarkSword iOS Exploit Kit to Target iPhone Users

Updated 3mo agoFirst seen Mar 28, 20264 sources

Proofpoint and other researchers said the Russia-linked threat group TA446—also tracked as Callisto, COLDRIVER, SEABORGIUM, and Star Blizzard—used the leaked DarkSword iOS exploit kit in a targeted spear-phishing campaign aimed at compromising iPhone users. On March 26, the actor sent spoofed Atlantic Council "discussion invitation" emails from compromised accounts, redirecting selected recipients to DarkSword infrastructure that delivered the GHOSTBLADE dataminer, while non-iPhone users were reportedly shown a benign PDF decoy. Researchers said this is the first observed case of TA446 targeting Apple devices and iCloud-related access.

The campaign was linked to TA446 through infrastructure overlaps, including VirusTotal samples referencing a TA446 second-stage domain and URLScan evidence showing a TA446-controlled domain serving DarkSword components. The operation also appeared broader than the group’s typical espionage activity, with targeting spanning government, think tanks, higher education, financial, and legal organizations. Apple separately warned users running older iOS and iPadOS versions to update because of active web-based attacks, while researchers cautioned that the leaked GitHub version of DarkSword could reduce the barrier to entry for advanced iPhone exploitation and help turn a nation-state capability into more widely available malware.

Share:
TA446 Uses DarkSword iOS Exploit Kit to Target iPhone Users
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Mar 31, 20263mo ago

Apple moves to backport DarkSword protections to older iOS 18 versions

By 2026-03-31, Apple said it would push rare backported security patches to protect users on older iOS 18 versions from DarkSword-related exploitation. The move followed criticism that affected users who had not upgraded remained exposed despite active attacks.

Apple Will Push Out Rare ‘Backported’ Patches to Protect iOS 18 Users From DarkSword Hacking Tool | WIRED
Mar 28, 20263mo ago

Proofpoint publicly discloses TA446's DarkSword iPhone campaign

On 2026-03-28, Proofpoint disclosed the targeted spear-phishing campaign using the leaked DarkSword iOS exploit kit and assessed it as a broader-than-usual TA446 operation. The disclosure highlighted the group's shift into Apple-device and iCloud-focused targeting.

Apple warns users on older iOS and iPadOS versions to update

Apple issued warnings for users running older iOS and iPadOS versions to update their devices because of active web-based attacks. The warning coincided with public reporting on DarkSword exploitation activity.

Researchers link TA446 infrastructure to DarkSword components

Proofpoint and other researchers connected the phishing activity to TA446 using infrastructure overlaps, including VirusTotal samples referencing a TA446 second-stage domain and URLScan evidence of a TA446-controlled domain delivering DarkSword components.

Leaked DarkSword exploit kit becomes publicly available on GitHub

Researchers said a leaked GitHub version of the DarkSword iOS exploit kit became available prior to the observed campaign, lowering the barrier to entry for advanced iOS exploitation and potentially commoditizing a previously nation-state-grade capability.

Mar 26, 20263mo ago

TA446 uses DarkSword to target iPhone users and deliver GHOSTBLADE

In the same 2026-03-26 campaign, researchers found that iPhone users were redirected to DarkSword exploit infrastructure while non-iPhone users received a benign PDF decoy. The exploit chain was used to deliver the GHOSTBLADE dataminer and pursue iCloud-related access, marking the first observed TA446 targeting of Apple devices.

TA446 sends Atlantic Council-themed phishing emails from compromised accounts

On 2026-03-26, Proofpoint observed a surge of spoofed Atlantic Council discussion-invitation emails sent from compromised accounts and attributed with high confidence to Russia-linked TA446. The campaign targeted organizations across government, think tanks, higher education, financial, and legal sectors.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

32 LINKEDOpen in app
Threat actors
2 linked
Affected products
10 linked
IphoneIosGithubIcloudVirustotalWhatsappTwitterIpadosIpadLinkedin
Organizations
16 linked
AppleProofpointGitHubMalforsGoogleAtlantic CouncilDoubleYouiVerifyWIREDRedditVirustotalLinkedinLookoutXURLscan.ioSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.