TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

2026-03-28T07:24:05Z60a6dfe41589dcf27034f0f0e954a6ad5b5ed92508ff4f83d1b77a4875b7a00d
APMAitM phishingApple lock‑screen alertsBearlyfyCISA KEVCVE-2025-53521DarkSwordF5 BIG-IPGenieLocker ransomware','LangChain','LangGraph','secrets leakageOAuth abuseOpen VSXPyPITA446TeamPCPTikTok for BusinessTrivy CI/CDVS Code extensionactive exploitationdevice code phishingiOS exploit kitlitellmpre‑publish bypassspear‑phishingsupply chain compromisetelnyx

What happened

News roundup covering multiple active high-risk incidents and supply‑chain attacks: Russian-linked TA446 is deploying the leaked DarkSword iOS exploit kit via targeted spear‑phishing; CISA added CVE-2025-53521 (F5 BIG-IP APM RCE, CVSSv4 9.3) to the KEV for observed exploitation; TeamPCP pushed malicious versions to PyPI (telnyx) and backdoored litellm via compromised CI/CD; device‑code OAuth phishing, WebRTC payment skimmers, and other large campaigns (malvertising delivering ScreenConnect with BYOVD driver to disable EDR) are active; multiple framework and extension vulnerabilities (LangChain

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
60a6dfe41589dcf27034f0f0e954a6ad5b5ed92508ff4f83d1b77a4875b7a00d
Enrichment time
2026-03-28T07:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign · Baitaphish