← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Chinese Threat Actor Uses Leaked DarkSword Exploit Kit to Deploy GHOSTBLADE on iOS

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Chinese threat actor targets iOS devices with leaked DarkSword exploit kit.
  • Campaign uses fake AWS sign-in pages to deploy GHOSTBLADE malware.
  • DarkSword targets iOS versions 18.4-18.7 and steals credentials.
  • Leak of DarkSword source code led to wider exploitation by other actors.

DarkSword Exploit Kit Utilized in New Campaign

An unidentified Chinese threat actor has been observed conducting a campaign against Apple iOS devices. The actor is leveraging a publicly leaked version of the DarkSword exploit kit, which targets iOS versions 18.4 through 18.7. This kit exploits now-patched vulnerabilities to execute JavaScript and deploy the GHOSTBLADE information-stealing malware.

Campaign Infrastructure and Targets

Attack surface management platform Censys identified the threat actor operating over 100 web properties. Most of these are fake Amazon Web Services (AWS) sign-in pages hosted on a domain that also hosts the exploit toolkit. The hosting infrastructure is concentrated in Hong Kong but extends to Japan, the United States, and Europe, indicating a broad reach for the campaign.

Proliferation Following Source Code Leak

DarkSword, initially discovered by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, is a full-chain exploit kit previously used by commercial surveillance vendors and suspected state-sponsored actors. Its use has expanded significantly after its source code was publicly leaked, allowing other threat actors to adopt and deploy it. Censys findings show multiple login panels for "DarkSword Admin" across various countries, some with Chinese-language fields.

Attack Methodology

The attack typically begins when a victim visits one of the operator's malicious domains, such as an AWS console impersonation or an Apple ID sign-in page. This action loads a malicious iframe element that triggers JavaScript, initiating the DarkSword exploit chain. Upon successful exploitation, the GHOSTBLADE modules are deployed, designed to steal sensitive information including keychain, iCloud, and Wi-Fi credentials.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A Chinese threat actor is using a publicly leaked version of the DarkSword exploit kit to target Apple iOS devices, deploying the GHOSTBLADE information-stealing malware. The campaign involves over 100 web properties, many impersonating AWS sign-in pages, to deliver the exploit chain. This development indicates the broader proliferation of the DarkSword kit following its source code leak, enabling more threat actors to conduct iOS attacks.