Trellix Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns

Trellix Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns

DarkSword, JSCeal, Axios, Bitter APT, and APT28 campaigns reveal evolving tactics targeting iPhones, Southeast Asia, software supply chains, diplomatic organizations, and European governments.

Listen to this article

0:00

Press play to start listening

Trellix’s Advanced Research Center has published its latest SecondSight Threat Hunting Report, covering cyber activity observed between January 1 and June 30, 2026. The report, shared with Hackread.com, details campaigns involving targeted phishing, trusted software, and evasion techniques.

DarkSword iOS Exploit Kit Targets Senior Officials

Trellix found a DarkSword iOS exploit campaign in which attackers sent four emails within 66 minutes to senior officials at NATO-aligned organizations while posing as Atlantic Council president Frederick Kempe.

The emails invited recipients to a fake “Closed-Door Strategic Discussion.” Among those targeted were officials from a Central European presidential office, a European foreign affairs ministry, a US federal agency, and a European aerospace company.

The messages led to phishing pages hosting the DarkSword exploit chain for iOS 18.4 through 18.7. The exploit chain used six vulnerabilities:

Tapping the malicious link could compromise a vulnerable iPhone without further interaction. The attackers also filtered visitors on the server side. Security scanners were shown a clean PDF, while visitors matching the target locations received the exploit.

Trellix linked the campaign with high confidence to a Russian actor whose activity is consistent with Star Blizzard. Researchers said attribution of the DarkSword exploit kit itself was less certain.

JSCeal Hides Inside Node.js

Trellix also examined a campaign targeting Southeast Asian organizations with JSCeal information stealer. It began with an encoded PowerShell script that disabled system proxy settings and downloaded Node.js and an encrypted application script. Node.js was run from directories named to resemble legitimate system components.

JSCeal decrypted its payload in memory with AES-256-CBC and used Brotli to decompress it before loading it through the V8 engine. It could steal browser passwords, cookies, cryptocurrency wallet data, keystrokes, and screenshots.

Other Campaigns

On March 31, attackers compromised the npm account of Axios’s lead maintainer and published malicious versions 1.14.1 and 0.30.4. The Axios source code itself was left untouched, but the packages included the malicious plain-crypto-js dependency, which used its installation process to deploy platform-specific RATs from sfrclak(.)com:8000 before deleting itself.

According to Trellix, execution was observed in 3% of exposed environments. The report also reveals a June 2026 FIFA-themed Bitter APT campaign targeting a European embassy in Asia.

“The email was cleverly disguised as a reply within a legitimate-appearing diplomatic invitation thread regarding a ‘FIFA World Cup themed event,’ enhancing its credibility,” the Trellix report states.

Attackers hijacked a diplomatic email thread and delivered a ZIP containing a VHDX image with an .lnk file that launched PowerShell and deployed BDarkRAT through a scheduled task. Trellix linked this activity to an October 2025 campaign because of a reused target and domain (hannahsgpsappcom).

APT28 (aka Fancy Bear) targeted government and defense organizations in nine Eastern European countries in late January. The group weaponized CVE-2026-21509 within 24 hours of its public disclosure and disguised RTF files with .doc extensions that delivered either the CovenantGrunt implant, which used filen.io for C2, or NotDoor, an Outlook VBA backdoor capable of stealing email data and receiving attacker commands.

Trellix said its Email Security blocked all 29 malicious emails before delivery.

The five cases cover iPhone exploitation, npm package compromise, credential theft, diplomatic phishing, and government espionage observed during the first half of 2026.

Commenting on Trellix’s findings, Jason Soroko, Senior Fellow at Sectigo, a Scottsdale, Arizona-based provider of certificate lifecycle management (CLM), said: “Organizations should not treat a known sender or familiar application as proof that activity is safe. Trellix found attacks using compromised government accounts and legitimate cloud services.”

“Threat hunting should examine what trusted software launches, which credentials it accesses, and where it connects. Keep patching urgent, including phones, but also investigate exposure before the fix. Removing the package does not resolve stolen access,” he added.

(Photo by Jayson Hinrichsen on Unsplash)

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts