News › security

Chinese Threat Actor Uses Leaked DarkSword Kit to Target iOS with GHOSTBLADE

By Zayden R., August 3, 2026

A Chinese threat actor is exploiting a leaked DarkSword exploit kit to deploy GHOSTBLADE malware on iOS devices, targeting versions 18.4 to 18.7. This campaign involves over 100 fake web properties posing as AWS and Apple ID login pages.

In a concerning development for mobile security, an unidentified Chinese threat actor has been using the publicly leaked DarkSword exploit kit to compromise iOS devices by deploying the GHOSTBLADE malware. This exploit targets iOS versions 18.4 through 18.7, taking advantage of now-patched vulnerabilities to execute malicious JavaScript that facilitates the malware's installation. Engineers should be aware of this threat, as it highlights the persistent risks associated with outdated software and underscores the importance of timely updates.

The DarkSword kit, initially discovered by Google Threat Intelligence Group, iVerify, and Lookout earlier this year, has been linked to commercial surveillance vendors and suspected state-sponsored activities. The leak of its source code has led to a proliferation of attacks, with the latest campaign identified by Censys involving over 100 fake web properties. These sites masquerade as AWS and Apple ID login pages, aiming to harvest credentials and further the reach of the GHOSTBLADE malware.

Censys' analysis reveals that the infrastructure supporting these attacks is concentrated in Hong Kong but extends to Japan, the United States, and Europe. Notably, the campaign's infrastructure includes a Singapore-based host running multiple exploit-panel front ends and a Hong Kong server serving as an Apple ID credential-harvesting decoy. Engineers should be vigilant in monitoring traffic to these regions and implementing robust security measures to mitigate potential intrusions.

This incident serves as a stark reminder of the evolving threat landscape and the need for continuous vigilance in the cybersecurity domain. Organizations are advised to review their security postures, ensure all systems are up-to-date, and educate users about the risks of phishing and credential theft.

Sources

Practice this on a real machine

The Linux Camp teaches these topics as hands-on labs on real virtual machines, verified as you type.