VYPR
researchPublished Aug 3, 2026· Updated Aug 10, 2026· 3 sources

Chinese Threat Actor Deploys GHOSTBLADE on iOS Using Leaked DarkSword Exploit Kit

A Chinese threat actor is actively targeting iOS devices with the GHOSTBLADE information-stealing malware by leveraging a publicly leaked version of the sophisticated DarkSword exploit kit.

An unknown Chinese-speaking threat actor has been observed orchestrating a campaign that specifically targets Apple iOS devices, utilizing a publicly leaked version of the DarkSword exploit kit. Security researchers at Censys identified the actor operating over 100 web properties, many of which are designed to impersonate Amazon Web Services (AWS) sign-in pages, and are used to host the exploit toolkit.

The DarkSword exploit kit, initially detailed earlier this year by Google Threat Intelligence Group, iVerify, and Lookout, is a comprehensive toolchain capable of full-chain exploits. It is believed to have been previously employed by commercial surveillance vendors and suspected state-sponsored actors in targeted attacks across Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025. The kit specifically targets iOS versions 18.4 through 18.7 and has been known to use watering hole attacks to trigger now-patched vulnerabilities in Apple's mobile operating system.

Upon successful exploitation, the kit executes JavaScript that facilitates the deployment of GHOSTBLADE, an information-stealing malware. The expansion of DarkSword's use is a direct consequence of its source code being leaked, which has enabled other threat actors to adopt and deploy it. Censys's analysis revealed that the login panel for a component named "DarkSword Admin" was hosted on multiple servers across three countries as of July 30, 2026. Additionally, one Singapore-based host was found to be running three distinct exploit-panel front ends, alongside a Hong Kong host that bundled a decoy Apple ID credential-harvesting page.

The attack methodology is consistent: victims are lured to one of the operator's domains, often an impersonated AWS console or an Apple ID sign-in page. A malicious iframe embedded on these pages then loads JavaScript, initiating the DarkSword exploit chain. This process ultimately leads to the installation of GHOSTBLADE modules on the compromised iOS device.

Once GHOSTBLADE is active, it deploys modules designed to exfiltrate credentials from the device's keychain, iCloud, and Wi-Fi configurations, and then proceeds to sweep for and exfiltrate files. The harvested data is packaged and sent to attacker-controlled endpoints. The threat actor then accesses one of several administration panels—DarkSword Admin, Decode Dashboard, or C2 Control Panel—to retrieve the stolen information.

Evidence suggests the threat actor is using the leaked kit directly, evidenced by a shared staging-page hash and Russian-language code comments inherited from the original source. Notably, one of the compromised hosts also previously hosted an administration panel for Coruna, an older iOS exploit kit, hinting at potential overlap or shared infrastructure with other threat groups, possibly including UNC6353, which has been linked to attacks on Ukrainian targets.

Further investigation by Censys uncovered an open directory listing in Frankfurt containing the operator's tooling. This included an SSH key comment referencing "jkcing@apt," a web-content fuzzer, and mentions of a previously undocumented malware family dubbed Thorn C2. The "C2 Control Panel" itself features a distinct visual design with a dark background, red accents, an animated particle effect, and a visible Telegram contact link for the "Asia-Pacific Group," providing a direct communication channel for the operator.

The DarkSword iOS exploit kit campaign has significantly expanded its infrastructure, now encompassing 180 web properties and 27 distinct hosts. Researchers noted that while the attacker infrastructure rotates rapidly, with servers being replaced in days, recognizable panel and staging-page content, along with stable page-body hashes, persist, offering a more reliable method for detection than solely relying on IP or domain blocklists.

This new report indicates that the sophisticated DarkSword exploit kit, previously associated with nation-state actors and Chinese threat groups, is now being offered for sale on underground forums. Furthermore, a separate exploit chain known as Coruna is also proliferating, suggesting a broader trend of advanced iOS exploitation tools becoming accessible to a wider range of organized cybercrime operations beyond state-sponsored or specific APT groups.

Synthesized by Vypr AI