MEDIUMApt
Global

TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

Saturday, March 28, 2026 at 07:07 AM UTC·Source: The Hacker News

Updated: Thursday, April 2, 2026 at 05:46 PM UTC

Executive Summary

Proofpoint has disclosed details of a targeted email campaign in which threat actors with ties to Russia are leveraging the recently disclosed DarkSword exploit kit to target iOS devices. The activity has been attributed with high confidence to the Russian state-sponsored threat group known as TA446, which is also tracked by the broader cybersecurity community under the monikers Callisto,

Analysis

Proofpoint has disclosed details of a targeted email campaign in which threat actors with ties to Russia are leveraging the recently disclosed DarkSword exploit kit to target iOS devices. The activity has been attributed with high confidence to the Russian state-sponsored threat group known as TA446, which is also tracked by the broader cybersecurity community under the monikers Callisto,
Source Attribution

Originally published by The Hacker News on Mar 28, 2026.

Related Threats