Threats · 169 days ago
Star Blizzard, a Russian state-linked APT, has adopted the DarkSword iOS exploit kit to deliver GhostBlade and harvest iCloud credentials. Proofpoint observed a March 26 spike in link-based phishing emails from compromised senders that redirected iPhone browsers to the exploit. The campaign targets government, higher education, financial, legal entities, and think tanks. This marks the group's first observed focus on Apple devices and iCloud accounts.
1 source covering this story
Russian APT Star Blizzard Adopts DarkSword iOS Exploit Kit
The state-sponsored group’s campaign has targeted government, higher education, financial, and legal entities, as well as think tanks.
Part of the PlainSec briefing for 2026-03-31