Proofpoint and other researchers said the Russia-linked threat group TA446—also tracked as Callisto, COLDRIVER, SEABORGIUM, and Star Blizzard—used the leaked DarkSword iOS exploit kit in a targeted spear-phishing campaign aimed at compromising iPhone users. On March 26, the actor sent spoofed Atlantic Council "discussion invitation" emails from compromised accounts, redirecting selected recipients to DarkSword infrastructure that delivered the GHOSTBLADE dataminer, while non-iPhone users were reportedly shown a benign PDF decoy. Researchers said this is the first observed case of TA446 targeting Apple devices and iCloud-related access.
The campaign was linked to TA446 through infrastructure overlaps, including VirusTotal samples referencing a TA446 second-stage domain and URLScan evidence showing a TA446-controlled domain serving DarkSword components. The operation also appeared broader than the group’s typical espionage activity, with targeting spanning government, think tanks, higher education, financial, and legal organizations. Apple separately warned users running older iOS and iPadOS versions to update because of active web-based attacks, while researchers cautioned that the leaked GitHub version of DarkSword could reduce the barrier to entry for advanced iPhone exploitation and help turn a nation-state capability into more widely available malware.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
By 2026-03-31, Apple said it would push rare backported security patches to protect users on older iOS 18 versions from DarkSword-related exploitation. The move followed criticism that affected users who had not upgraded remained exposed despite active attacks.
On 2026-03-28, Proofpoint disclosed the targeted spear-phishing campaign using the leaked DarkSword iOS exploit kit and assessed it as a broader-than-usual TA446 operation. The disclosure highlighted the group's shift into Apple-device and iCloud-focused targeting.
Apple issued warnings for users running older iOS and iPadOS versions to update their devices because of active web-based attacks. The warning coincided with public reporting on DarkSword exploitation activity.
Proofpoint and other researchers connected the phishing activity to TA446 using infrastructure overlaps, including VirusTotal samples referencing a TA446 second-stage domain and URLScan evidence of a TA446-controlled domain delivering DarkSword components.
Researchers said a leaked GitHub version of the DarkSword iOS exploit kit became available prior to the observed campaign, lowering the barrier to entry for advanced iOS exploitation and potentially commoditizing a previously nation-state-grade capability.
In the same 2026-03-26 campaign, researchers found that iPhone users were redirected to DarkSword exploit infrastructure while non-iPhone users received a benign PDF decoy. The exploit chain was used to deliver the GHOSTBLADE dataminer and pursue iCloud-related access, marking the first observed TA446 targeting of Apple devices.
On 2026-03-26, Proofpoint observed a surge of spoofed Atlantic Council discussion-invitation emails sent from compromised accounts and attributed with high confidence to Russia-linked TA446. The campaign targeted organizations across government, think tanks, higher education, financial, and legal sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
wired.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.