Threats & Adversaries · APT / Espionage

Russian APT expands to iOS to harvest iCloud credentials

Star Blizzard, a Russian state-linked APT, has adopted the DarkSword iOS exploit kit to deliver GhostBlade and harvest iCloud credentials. Proofpoint observed a March 26 spike in link-based phishing emails from compromised senders that redirected iPhone browsers to the exploit. The campaign targets government, higher education, financial, legal entities, and think tanks. This marks the group's first observed focus on Apple devices and iCloud accounts.

1 source · Mar 30

Timeline

Sources

Part of the PlainSec briefing for 2026-03-31

Every edition of this story: Russian APT expands to iOS to harvest iCloud credentials

More from today