VMTech
Discuss a project

Leaked DarkSword exploit kit drives GHOSTBLADE attacks on iOS

Leaked DarkSword exploit kit drives GHOSTBLADE attacks on iOS

An unknown Chinese threat actor is using a leaked copy of the DarkSword exploit kit to compromise Apple iOS devices and deploy the GHOSTBLADE information stealer. Censys identified more than 100 web properties operated by the actor, most presenting fake Amazon Web Services sign-in pages on infrastructure that also hosts the exploit tooling.

The hosting is concentrated in Hong Kong, with infrastructure extending into Japan, the United States, and Europe. As of July 30, 2026, Censys had matched the DarkSword Admin login page to seven hosts in three countries.

From sign-in decoy to device compromise

The attack begins when a victim visits an operator-controlled domain, typically an AWS console impersonation subdomain or an Apple ID sign-in page. A malicious iframe loads JavaScript that triggers the DarkSword chain and ultimately installs GHOSTBLADE modules.

DarkSword targets iOS 18.4 through 18.7 and uses now-patched vulnerabilities in Apple's mobile operating system. After successful exploitation, GHOSTBLADE can dump keychain, iCloud, and Wi-Fi credentials, sweep the device for files, package the harvested data, and send it to attacker-controlled endpoints.

The campaign illustrates how borrowed trust as a core cyberattack tactic can extend beyond conventional credential phishing when trusted brands and familiar login experiences are used to bring victims into an exploit chain.

Evidence points to the leaked kit

Censys said the cluster runs the leaked DarkSword kit rather than a reimplementation. Its evidence includes a shared staging-page hash and Russian-language code comments retained from the leaked source.

Researchers found three panel types used to retrieve stolen information: DarkSword Admin, Decode Dashboard, and C2 Control Panel. One Singapore-based host ran three distinct exploit-panel front ends, while a Hong Kong host combined the C2 panel with an Apple ID credential-harvesting decoy.

The C2 Control Panel displayed the name “Asia-Pacific Group” in Chinese and exposed a Telegram contact. Censys described it as the first direct contact channel recovered for this operator; the other identified panels presented only login gates.

A broader mobile exploitation ecosystem

DarkSword was documented by Google Threat Intelligence Group, iVerify, and Lookout after being used in campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025. Its use broadened after the source code became public, allowing additional actors to adopt the chain.

The now-inactive Singapore host also carried an administration panel for Coruna, an older exploit kit targeting iOS 3.0 through 17.2.1. Censys noted evidence that UNC6353 used both kits in attacks against Ukrainian targets. An exposed directory in Frankfurt additionally revealed operator tooling, an SSH key comment, a web-content fuzzer, and references to a previously undocumented malware family called Thorn C2.

Business implications

Organizations should treat imitation cloud and Apple authentication pages as potential exploit-delivery infrastructure, not solely as credential-theft lures. Prompt iOS patching reduces exposure to the vulnerabilities used by DarkSword, while managed-device visibility, domain controls, and procedures for resetting compromised credentials can limit the operational impact if a device reaches this infrastructure.

#iossecurity#mobilemalware#threatintel#cybersecurity
Open analytics
On the site 2 views
min read 4 05.08.2026
Instagram

Leaked DarkSword exploit kit drives GHOSTBLADE attacks on iOS

Open the post on Instagram ↗