TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

Threat actors with connections to Russia are using the recently revealed DarkSword exploit kit to target iOS devices in a targeted email campaign, according to information released by Proofpoint.

The Russian state-sponsored threat group TA446, which is also monitored by the larger cybersecurity community under the names Callisto, COLDRIVER, and Star Blizzard (previously SEABORGIUM), has been highly confidently linked to the activity. It is believed to be connected to the Federal Security Service (FSB) of Russia.

The hacker collective is well-known for spear-phishing attempts to get login credentials from potential targets. But over the past year, the threat actor has launched attacks that have targeted users’ WhatsApp accounts and used several proprietary malware families to steal private information.

The most recent activity, as reported by Proofpoint and Malfors, entails utilizing phony “discussion invitation” emails that impersonate the Atlantic Council in order to make it easier for the DarkSword exploit kit to spread the dataminer malware GHOSTBLADE read more about TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *