Full Report
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit. "
Analysis Summary
# Threat Actor: Asia-Pacific Group (亚太集团)
## Attribution & Identity
* **Actor Name:** Asia-Pacific Group (亚太集团 / Yata Group)
* **Origin:** China (Suspected based on Chinese-language panel labels and group naming)
* **Associated Groups:** Potential links to **UNC6353** (due to shared use of exploit kits) and mentions of "jkcing@apt" in SSH metadata.
## Activity Summary
This unknown actor is currently conducting a wide-scale exploitation campaign targeting Apple iOS devices. They are leveraging a leaked version of the **DarkSword** exploit kit. The operation involves over 100 web properties used for credential harvesting and malware delivery, with infrastructure concentrated in Hong Kong, Singapore, the US, and Japan.
## Tactics, Techniques & Procedures
* **Watering Hole Attacks:** Using compromised or attacker-controlled websites to lure victims.
* **Social Engineering:** Creating fake AWS console sign-in pages and Apple ID login decoys to harvest credentials.
* **Exploitation:** Utilizing a full-chain exploit kit (DarkSword) targeting iOS vulnerabilities (versions 18.4 to 18.7).
* **Web Shells/Panels:** Usage of multiple administrative panels including "DarkSword Admin," "Decode Dashboard," and "C2 Control Panel."
* **Payload Execution:** Loading malicious iframes to trigger JavaScript-based exploit chains.
* **Exfiltration:** Automated packaging and transmission of stolen keychain, iCloud, and Wi-Fi credentials.
## Targeting
* **Sectors:** Likely Cloud users (AWS) and general Apple ecosystem users.
* **Geography:** Hosting infrastructure found in Hong Kong, Singapore, Japan, USA, Europe, and Frankfurt. Historically associated kits have targeted Saudi Arabia, Turkey, Malaysia, and Ukraine.
* **Victims:** Users of iOS versions 18.4 through 18.7.
## Tools & Infrastructure
* **Malware Families:**
* **GHOSTBLADE:** An information-stealer targeting iOS.
* **Thorn C2:** A previously undocumented malware family discovered in open directories.
* **Exploit Kits:** DarkSword (iOS 18.4-18.7) and Coruna (iOS 3.0-17.2.1).
* **Infrastructure (Defanged):**
* **IPs:** `38.181.52[.]95`, `103.106.190[.]217`, `38.22.89[.]117`, `103.97.128[.]67`, `162.4.136[.]30`, `223.26.63[.]56`, `151.243.126[.]191`, `107.175.49[.]181`, `103.238.129[.]112`, `103.226.155[.]200`, `202.8.120[.]249`, `93.152.221[.]37`.
* **Communication:** Telegram contact `hxxps://t[.]me/YATA0000`.
## Implications
The leak of professional-grade exploit kits like DarkSword has significantly lowered the barrier to entry for various threat actors. The "Asia-Pacific Group" demonstrates the ability to rapidly operationalize leaked state-level or commercial surveillance tools to target mobile users globally. This suggests a persistent threat to mobile privacy and corporate cloud security via credential theft.
## Mitigations
* **Update Software:** Ensure iOS devices are updated beyond version 18.7 to patch the vulnerabilities utilized by the DarkSword kit.
* **Multi-Factor Authentication (MFA):** Implement hardware-based MFA (like FIDO2 keys) for AWS and Apple ID accounts to prevent credential harvesting.
* **Network Filtering:** Block known malicious IPs and domains associated with the DarkSword panels and GHOSTBLADE C2 infrastructure.
* **Mobile Threat Defense (MTD):** Deploy MTD solutions on enterprise mobile devices to detect anomalies and unauthorized exfiltration attempts.