An unidentified Chinese threat actor has been observed conducting a campaign against Apple iOS devices. The actor is leveraging a publicly leaked version of the DarkSword exploit kit, which targets iOS versions 18.4 through 18.7. This kit exploits now-patched vulnerabilities to execute JavaScript and deploy the GHOSTBLADE information-stealing malware.
Attack surface management platform Censys identified the threat actor operating over 100 web properties. Most of these are fake Amazon Web Services (AWS) sign-in pages hosted on a domain that also hosts the exploit toolkit. The hosting infrastructure is concentrated in Hong Kong but extends to Japan, the United States, and Europe, indicating a broad reach for the campaign.
DarkSword, initially discovered by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, is a full-chain exploit kit previously used by commercial surveillance vendors and suspected state-sponsored actors. Its use has expanded significantly after its source code was publicly leaked, allowing other threat actors to adopt and deploy it. Censys findings show multiple login panels for "DarkSword Admin" across various countries, some with Chinese-language fields.
The attack typically begins when a victim visits one of the operator's malicious domains, such as an AWS console impersonation or an Apple ID sign-in page. This action loads a malicious iframe element that triggers JavaScript, initiating the DarkSword exploit chain. Upon successful exploitation, the GHOSTBLADE modules are deployed, designed to steal sensitive information including keychain, iCloud, and Wi-Fi credentials.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A Chinese threat actor is using a publicly leaked version of the DarkSword exploit kit to target Apple iOS devices, deploying the GHOSTBLADE information-stealing malware. The campaign involves over 100 web properties, many impersonating AWS sign-in pages, to deliver the exploit chain. This development indicates the broader proliferation of the DarkSword kit following its source code leak, enabling more threat actors to conduct iOS attacks.