Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Anthropic’s Claude is soaring in popularity among paying consumers

Citrix NetScaler memory overread bug under active investigation for CVE-2026-3055 (CVSS 9.3)

TA446 deploys DarkSword iOS exploit kit in targeted spear-phishing campaign

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » TA446 deploys DarkSword iOS exploit kit in targeted spear-phishing campaign
Identity

TA446 deploys DarkSword iOS exploit kit in targeted spear-phishing campaign

By March 28, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananMarch 28, 2026Mobile Security / Email Security

Proofpoint has revealed details of a targeted email campaign in which Russian-linked attackers leveraged the recently revealed DarkSword exploit kit to target iOS devices.

We have high confidence that this activity is the work of a Russian state-sponsored threat group known as TA446, and is also tracked by the broader cybersecurity community under the names Callisto, COLDRIVER, and Star Blizzard (formerly SEABORGIUM). It is believed to be affiliated with Russia’s Federal Security Service (FSB).

This hacker group is known for spear phishing campaigns aimed at collecting credentials from targets of interest. However, attacks launched by this threat actor over the past year have targeted victims’ WhatsApp accounts and leveraged various custom malware families to steal sensitive data.

The latest activity highlighted by Proofpoint and Malfors includes using fake “discussion invitation” emails impersonating the Atlantic Council to facilitate the distribution of the dataminer malware GHOSTBLADE via the DarkSword exploit kit. The email was sent from a compromised sender on March 26, 2026. One of the email recipients was Leonid Volkov, a prominent Russian opposition politician and political director of the Anti-Corruption Foundation.

Automated analysis triggered by Proofpoint’s security tools was allegedly redirected to a benign decoy PDF document. This is likely due to server-side filtering introduced solely to direct iPhone browsers to exploit kits.

“While TA446 has not previously been observed targeting users’ iCloud accounts or Apple devices, the adoption of the leaked DarkSword iOS exploit kit allows this attacker to target iOS devices,” Proofpoint said.

The enterprise security firm also noted a “significant increase” in the volume of emails from threat actors over the past two weeks, adding that these attacks led to the deployment of a known backdoor called MAYBEROBOT via a password-protected ZIP file.

This group’s use of DarkSword is also supported by the fact that a DarkSword loader uploaded to VirusTotal was found to reference “escofiringbijou”.[.]com’ is a second-stage domain attributed to a threat actor.

URL scan[.]io results revealed that a domain controlled by TA446 served the DarkSword exploit kit, which included an initial redirector, exploit loader, remote code execution, and Pointer Authentication Code (PAC) bypass components. However, there is no evidence that Escape from the Sandbox was ever distributed.

TA446 is suspected of reusing the DarkSword exploit kit for credential harvesting and information gathering, and Proofpoint noted that the targets observed in the email campaign were “much broader than usual” and included governments, think tanks, higher education institutions, financial institutions, and corporations.

This raises the possibility that threat actors are leveraging the new capabilities provided by DarkSword as part of opportunistic campaigns against a broader set of targets.

The development comes as Apple began sending lock screen notifications to iPhones and iPads running older versions of iOS and iPadOS to warn users about web-based attacks and encourage them to install updates to block the threats. This unusual move shows that the company is treating this as a widespread threat that requires immediate response from users.

Apple’s warning also coincides with the leak of a new version of DarkSword on GitHub, raising concerns that it could fundamentally change the mobile threat landscape by democratizing access to exploits for nation states.

Justin Albrecht, lead researcher at Lookout, said the leaked plug-and-play version allows even unskilled attackers to deploy sophisticated iOS espionage kits and turn them into commodity malware.

Albrecht added, “Dark Sword refutes the conventional wisdom that iPhones are immune to cyber threats and that advanced mobile attacks are only used for targeted attacks against governments and high-ranking officials.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleCISA adds CVE-2025-53521 to KEV after active F5 BIG-IP APM exploit
Next Article Citrix NetScaler memory overread bug under active investigation for CVE-2026-3055 (CVSS 9.3)

Related Posts

Citrix NetScaler memory overread bug under active investigation for CVE-2026-3055 (CVSS 9.3)

March 28, 2026

CISA adds CVE-2025-53521 to KEV after active F5 BIG-IP APM exploit

March 28, 2026

Apple uses web-based exploit to send lock screen alerts to older iPhones

March 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Anthropic’s Claude is soaring in popularity among paying consumers

Citrix NetScaler memory overread bug under active investigation for CVE-2026-3055 (CVSS 9.3)

TA446 deploys DarkSword iOS exploit kit in targeted spear-phishing campaign

CISA adds CVE-2025-53521 to KEV after active F5 BIG-IP APM exploit

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.