BoletimSecAugust 5, 2026🇵🇹Translated from Portuguese

DarkSword Exploit Kit Expands to 180 Sites Targeting iPhone Users with Zero-Click Chain

The DarkSword exploit kit has significantly expanded its reach, now operating across 180 web properties distributed over 27 servers. The campaign targets iPhone users through malicious pages that mimic legitimate services including Apple and AWS.

Visitors with vulnerable versions of iOS 18.4 to iOS 18.7 can be compromised without any user interaction or file downloads. The kit fingerprints the device and loads tailored modules that chain six vulnerabilities to achieve remote code execution, sandbox escape, and privilege escalation directly in the browser.

Following successful exploitation, GHOSTBLADE components harvest sensitive data from the Keychain, iCloud-stored files, Wi-Fi credentials, and other local storage. All stolen information is sent to attacker-controlled dashboards while crash reports and system logs are wiped to obstruct forensic investigation.

The attack does not install persistent implants, yet operators can still exfiltrate substantial volumes of data during the brief active session. Infrastructure changes occur frequently; five of the seven servers displaying administrative panels on July 30, 2026, had not been active the previous week, demonstrating rapid rotation of domains and hosts to evade detection and blocking.

Related articles

BoletimSecMalware & Botnets

AmnesiaStealer Malware for macOS Hijacks Authenticated Browser Sessions via ClickFix and Chromium

A new macOS malware strain named AmnesiaStealer has emerged that combines infostealing, persistence mechanisms, and the ability to silently take over already authenticated browser sessions. The infection chain begins with a fake GitHub page that tricks victims into copying a malicious command into Terminal using the ClickFix social engineering technique. Once executed, the Rust-based payload collects system data, displays a fake installer window to capture the user password, and attempts to unlock the Keychain for protected credentials. Targeted data includes browser cookies, history, extensions, documents, Apple Notes, Telegram sessions, and cryptocurrency wallet information. A secondary module copies the browser profile and launches a hidden Chromium instance controlled through the Chrome DevTools Protocol, allowing attackers to interact with active sessions that have already passed multi-factor authentication. Persistence is achieved via a disguised LaunchDaemon, and the malware attempts to remove installation artifacts afterward.

HabrMalware & Botnets

GOFFEE Dissects Custom COW Agent Forked from Poseidon Mythic Implant

Angara Security researchers uncovered a custom Go-based Mythic C2 agent named COW used by the Russian-oriented APT group GOFFEE, also known as Paper Werewolf. The agent represents an independent development branch derived from the public Poseidon project rather than its Freyja fork. Samples were heavily protected with Garble obfuscation and a modified UPX packer that required manual header reconstruction for unpacking. Analysis of surviving strings, build paths, and architectural features confirmed Poseidon origins while revealing numerous custom modifications including Windows support, additional C2 profiles, and new command implementations. The group employs the agent alongside other tools such as PowerTaskel, MiRat, and BindSycler for persistent access to Linux and Windows systems across government, energy, telecom, and defense targets. Researchers traced multiple variants through VirusTotal and incident reports, documenting evolutionary changes in configuration handling and peer-to-peer communication mechanisms.

BoletimSecMalware & Botnets

Manic Android Malware Steals PINs via Transparent Overlay and Relays Data Through Nearby Infected Devices

A newly identified Android malware strain named Manic merges banking trojan, spyware, and remote access capabilities. The threat has been active since at least February 2026 and continues to receive updates that add anti-analysis features, in-memory code loading, and lock-screen credential theft. Manic monitors 169 financial, messaging, and government applications while using a transparent overlay on legitimate numeric keyboards to capture PINs without displaying a full fake banking screen. Stolen data can be forwarded through other compromised nearby devices even when the original phone lacks internet connectivity. Operators also leverage WebRTC sessions for live screen viewing and remote interaction. The malware additionally functions as a keylogger, intercepts SMS and notifications, and collects passwords, one-time codes, and recovery phrases. Security researchers recommend avoiding unknown APKs and scrutinizing requests for Accessibility Services or broad device control permissions.

AntiMalwareMalware & Botnets

Armored Likho Expands Arsenal with BusySnake RAT and AI-Driven Malware Development

The cybercrime group Armored Likho has introduced a new multi-platform trojan called BusySnake RAT that targets Windows, Linux, and macOS systems. Researchers at Kaspersky Lab identified three distinct versions of the malware, evolving from a Python implementation using Telegram bots for command-and-control to a GitLab-based variant and finally a fully rewritten Go version. In addition to custom development, the group has incorporated the open-source Kharon RAT to facilitate remote access and data exfiltration. Armored Likho has also shifted its infrastructure to private GitHub and GitLab repositories to hinder analysis. Most notably, the group now leverages large language models not only for initial access but also to generate tools for persistence and post-exploitation activities. Kaspersky security products continue to detect and block activity linked to the group.