By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Computing

TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

News Room
Last updated: 2026/04/01 at 12:33 AM
News Room Published 1 April 2026
Share
TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
SHARE

Ravie LakshmananMar 28, 2026Mobile Security / Email Security

Proofpoint has disclosed details of a targeted email campaign in which threat actors with ties to Russia are leveraging the recently disclosed DarkSword exploit kit to target iOS devices.

The activity has been attributed with high confidence to the Russian state-sponsored threat group known as TA446, which is also tracked by the broader cybersecurity community under the monikers Callisto, COLDRIVER, and Star Blizzard (formerly SEABORGIUM). It’s assessed to be affiliated with Russia’s Federal Security Service (FSB).

The hacking group is known for spear-phishing campaigns aimed at harvesting credentials from targets of interest. However, attacks mounted by the threat actor over the past year have targeted victims’ WhatsApp accounts, as well as leveraged various custom malware families to steal sensitive data.

The latest activity, highlighted by Proofpoint and Malfors, involves using fake “discussion invitation” emails spoofing the Atlantic Council to facilitate the delivery of GHOSTBLADE, a dataminer malware, via the DarkSword exploit kit. The emails were sent from compromised senders on March 26, 2026. One of the email recipients was Leonid Volkov, a prominent Russian opposition politician and the political director of the Anti-Corruption Foundation.

An automated analysis triggered by Proofpoint’s security tools is said to have redirected to a benign decoy PDF document, likely because of server-side filtering put in place to only lead iPhone browsers to the exploit kit.

“We have not previously observed TA446 target users’ iCloud accounts or Apple devices, but the adoption of the leaked DarkSword iOS exploit kit has now enabled the actor to target iOS devices,” Proofpoint said.

The enterprise security firm also noted that the volume of emails from the threat actor has been “significantly higher” in the last two weeks, adding that these attacks lead to the deployment of a known backdoor referred to as MAYBEROBOT via password-protected ZIP files.

The group’s use of DarkSword has also been corroborated by the fact that a DarkSword loader uploaded to VirusTotal has been found to reference “escofiringbijou[.]com,” a second-stage domain attributed to the threat actor.

A urlscan.io result has revealed that the TA446-controlled domain has served the DarkSword exploit kit, including the initial redirector, exploit loader, remote code execution, and Pointer Authentication Code (PAC) bypass components. However, there is no evidence that sandbox escapes were delivered.

It’s suspected that the TA446 is repurposing the DarkSword exploit kit for credential harvesting and intelligence collection, with Proofpoint noting that the targeting observed in the email campaign was “much wider than usual” and that it included government, think tank, higher education, financial, and legal entities.

This, in turn, has raised the possibility that the threat actor is leveraging the new capability afforded by DarkSword as part of an opportunistic campaign against a broader target set.

Greg Lesnewisch, staff threat researcher at Proofpoint, told The Hacker News that the attack likely leveraged a leaked version of DarkSword, which was taken directly from one of UNC6353’s watering holes and uploaded to GitHub, and that “TA446 is using the same version of the exploit kit UNC6353 was using.” It’s currently not known if any of these attacks were successful. However, Proofpoint said all messages targeting its customers were blocked.

The development comes as Apple has begun sending Lock Screen notifications to iPhones and iPads running older versions of iOS and iPadOS to alert users of web-based attacks and urging them to install the update to block the threat. The unusual step signals that the company is treating it as a broad enough threat requiring users’ immediate attention.

Apple’s warning also coincides with the leak of a new version of DarkSword on GitHub, raising concerns that they could democratize access to nation-state exploits, fundamentally shifting the mobile threat landscape.

Justin Albrecht, principal researcher at Lookout, said the leaked, plug-and-play version allows even unskilled threat actors to deploy the advanced iOS espionage kit, turning it into commodity malware.

“DarkSword refutes the common belief that iPhones are immune to cyber threats, and that advanced mobile attacks are only used in targeted efforts against governments and high-ranking officials,” Albrecht added.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article QCon London 2026:  Team Topologies as the ‘Infrastructure for Agency’ with AI QCon London 2026: Team Topologies as the ‘Infrastructure for Agency’ with AI
Next Article The jobs AI can’t do – and the young adults doing them The jobs AI can’t do – and the young adults doing them
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

The Next Evolution Of Hard Drives Could Be Even More Sci-Fi Than We Thought – BGR
The Next Evolution Of Hard Drives Could Be Even More Sci-Fi Than We Thought – BGR
News
JD.com and Unitree to open first offline store in Beijing, offering hands-on robot experience and on-site orders · TechNode
JD.com and Unitree to open first offline store in Beijing, offering hands-on robot experience and on-site orders · TechNode
Computing
Salesforce transforms Slackbot into the ultimate work assistant with 30 new AI features –  News
Salesforce transforms Slackbot into the ultimate work assistant with 30 new AI features – News
News
AI Has Flooded All the Weather Apps
AI Has Flooded All the Weather Apps
Gadget

You Might also Like

JD.com and Unitree to open first offline store in Beijing, offering hands-on robot experience and on-site orders · TechNode
Computing

JD.com and Unitree to open first offline store in Beijing, offering hands-on robot experience and on-site orders · TechNode

3 Min Read

Your access to this site has been limited by the site owner

0 Min Read
Social Media Accessibility​: Top Alt Text for Social Media Tips
Computing

Social Media Accessibility​: Top Alt Text for Social Media Tips

1 Min Read
ZepoteQ Earns an 87.4 Proof of Usefulness Score by Building Scalable SaaS Platforms and Business Automation Tools | HackerNoon
Computing

ZepoteQ Earns an 87.4 Proof of Usefulness Score by Building Scalable SaaS Platforms and Business Automation Tools | HackerNoon

0 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?