{"id":228498,"date":"2026-03-28T02:58:00","date_gmt":"2026-03-28T06:58:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/03\/28\/ta446-deploys-darksword-ios-exploit-kit-in-targeted-spear-phishing-campaign\/"},"modified":"2026-03-28T08:15:09","modified_gmt":"2026-03-28T12:15:09","slug":"ta446-deploys-darksword-ios-exploit-kit-in-targeted-spear-phishing-campaign","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/03\/28\/ta446-deploys-darksword-ios-exploit-kit-in-targeted-spear-phishing-campaign\/","title":{"rendered":"TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/ta446-deploys-leaked-darksword-ios.html\">TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/ta446-deploys-leaked-darksword-ios.html\">https:\/\/thehackernews.com\/2026\/03\/ta446-deploys-leaked-darksword-ios.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-03-28 02:58:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Mar 28, 2026<\/span><\/span><span class=\"p-tags\">Mobile Security \/ Email Security<\/span><\/p>\n<p>Proofpoint has disclosed details of a targeted email campaign in which threat actors with ties to Russia are leveraging the recently disclosed DarkSword exploit kit to target iOS devices.<\/p>\n<p>The activity has been attributed with high confidence to the Russian state-sponsored threat group known as TA446, which is also tracked by the broader cybersecurity community under the monikers Callisto, COLDRIVER, and Star Blizzard (formerly SEABORGIUM). It&#8217;s assessed to be affiliated with Russia&#8217;s Federal Security Service (FSB).<\/p>\n<p>The hacking group is known for spear-phishing campaigns aimed at harvesting credentials from targets of interest. However, attacks mounted by the threat actor over the past year have targeted victims&#8217; WhatsApp accounts, as well as leveraged various custom malware families to steal sensitive data.<\/p>\n<p>The latest activity, highlighted by Proofpoint and Malfors, involves using fake &#8220;discussion invitation&#8221; emails spoofing the Atlantic Council to facilitate the delivery of GHOSTBLADE, a dataminer malware, via the DarkSword exploit kit. The emails were sent from compromised senders on March 26, 2026. One of the email recipients was Leonid Volkov, a prominent Russian opposition politician and the political director of the Anti-Corruption Foundation.<\/p>\n<p>An automated analysis triggered by Proofpoint&#8217;s security tools is said to have redirected to a benign decoy PDF document, likely because of server-side filtering put in place to only lead iPhone browsers to the exploit kit.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"902\" data-original-width=\"1288\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgm61T5g2RCi1buBkPlWD3T_xGs5RUmiXjTG542nx-Sbqkzmi2_TX9X_dxoKYWEjknwcRPCPHQFW2ZuxfN4NtPfgy9zmLZTR6FLHRneJ46bZjTHQXl1sctKIWNt8XRMgtyCStreIb-_J6iTNCG4uLHRkIwQ6j5T_UaPcK6232PO5DGIJxQtwx6AQ-JGc0lo\/s1600\/phish.jpg\"\/><\/p>\n<p>&#8220;We have not previously observed TA446 target users&#8217; iCloud accounts or Apple devices, but the adoption of the leaked DarkSword iOS exploit kit has now enabled the actor to target iOS devices,&#8221; Proofpoint said.<\/p>\n<p>The enterprise security firm also noted that the volume of emails from the threat actor has been &#8220;significantly higher&#8221; in the last two weeks, adding that these attacks lead to the deployment of a known backdoor referred&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/ta446-deploys-leaked-darksword-ios.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign https:\/\/thehackernews.com\/2026\/03\/ta446-deploys-leaked-darksword-ios.html Publish Date: 2026-03-28 02:58:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":228499,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhAX955shB28AQ8BgXC9lMJBSEWWtw5FVp3L9rxuVnBSsDMpj5Ssjh7cqxd7eJI_bES6b82XDHvxrH0U_cyEXwbS05QkUbSDPzP8ZGcjy2QD2-gY9utPDfcJ6EBO-nk3VayGUBUnesxmmGOH-AanOtkxxhPGyZ-5azN_kzflpKoqfW7U2m35ookIyuEYvFo\/s1600\/iphone-exploit.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31,32,25,34],"class_list":["post-228498","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit","tag-malware","tag-phishing","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/228498"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=228498"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/228498\/revisions"}],"predecessor-version":[{"id":228500,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/228498\/revisions\/228500"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/228499"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=228498"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=228498"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=228498"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}