# Russian State Group TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign

_Saturday, March 28, 2026 at 5:27 AM EDT · Security · Latest · Tier 2 — Notable_

![Russian State Group TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAX955shB28AQ8BgXC9lMJBSEWWtw5FVp3L9rxuVnBSsDMpj5Ssjh7cqxd7eJI_bES6b82XDHvxrH0U_cyEXwbS05QkUbSDPzP8ZGcjy2QD2-gY9utPDfcJ6EBO-nk3VayGUBUnesxmmGOH-AanOtkxxhPGyZ-5azN_kzflpKoqfW7U2m35ookIyuEYvFo/s1700-e365/iphone-exploit.jpg)

Proofpoint has disclosed a targeted spear-phishing campaign conducted by TA446, a Russian state-sponsored threat group also known as Callisto, deploying the leaked DarkSword exploit kit against iOS devices. The campaign represents an escalation in mobile-targeted attacks by nation-state actors and highlights the growing threat posed by leaked commercial exploit kits being weaponized in state-sponsored operations.

[Instagram]
Proofpoint has uncovered a Russian state-sponsored campaign using the leaked DarkSword iOS exploit kit to target users through spear-phishing emails. The threat actor TA446, also known as Callisto, has been attributed with high confidence. iOS users in targeted organizations should be on alert.

[LinkedIn]
Proofpoint has disclosed a targeted spear-phishing campaign conducted by TA446, a Russian state-sponsored threat group also known as Callisto, deploying the leaked DarkSword exploit kit against iOS devices. The campaign represents an escalation in mobile-targeted attacks by nation-state actors and highlights the growing threat posed by leaked commercial exploit kits being weaponized in state-sponsored operations.

## Sources


---
Canonical: https://techandbusiness.org/newswire/newsDraft.c19c82bd-fa67-49c2-a507-c786615e29ad
Retrieved: 2026-07-21T23:45:05.847Z
Publisher: Tech & Business (techandbusiness.org)
