Chinese Threat Actor Deploys GHOSTBLADE on iOS Using Leaked DarkSword Exploit Kit
A Chinese threat actor is actively targeting iOS devices with the GHOSTBLADE information-stealing malware by leveraging a publicly leaked version of the sophisticated DarkSword exploit kit.

An unknown Chinese-speaking threat actor has been observed orchestrating a campaign that specifically targets Apple iOS devices, utilizing a publicly leaked version of the DarkSword exploit kit. Security researchers at Censys identified the actor operating over 100 web properties, many of which are designed to impersonate Amazon Web Services (AWS) sign-in pages, and are used to host the exploit toolkit.
The DarkSword exploit kit, initially detailed earlier this year by Google Threat Intelligence Group, iVerify, and Lookout, is a comprehensive toolchain capable of full-chain exploits. It is believed to have been previously employed by commercial surveillance vendors and suspected state-sponsored actors in targeted attacks across Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025. The kit specifically targets iOS versions 18.4 through 18.7 and has been known to use watering hole attacks to trigger now-patched vulnerabilities in Apple's mobile operating system.
Upon successful exploitation, the kit executes JavaScript that facilitates the deployment of GHOSTBLADE, an information-stealing malware. The expansion of DarkSword's use is a direct consequence of its source code being leaked, which has enabled other threat actors to adopt and deploy it. Censys's analysis revealed that the login panel for a component named "DarkSword Admin" was hosted on multiple servers across three countries as of July 30, 2026. Additionally, one Singapore-based host was found to be running three distinct exploit-panel front ends, alongside a Hong Kong host that bundled a decoy Apple ID credential-harvesting page.
The attack methodology is consistent: victims are lured to one of the operator's domains, often an impersonated AWS console or an Apple ID sign-in page. A malicious iframe embedded on these pages then loads JavaScript, initiating the DarkSword exploit chain. This process ultimately leads to the installation of GHOSTBLADE modules on the compromised iOS device.
Once GHOSTBLADE is active, it deploys modules designed to exfiltrate credentials from the device's keychain, iCloud, and Wi-Fi configurations, and then proceeds to sweep for and exfiltrate files. The harvested data is packaged and sent to attacker-controlled endpoints. The threat actor then accesses one of several administration panels—DarkSword Admin, Decode Dashboard, or C2 Control Panel—to retrieve the stolen information.
Evidence suggests the threat actor is using the leaked kit directly, evidenced by a shared staging-page hash and Russian-language code comments inherited from the original source. Notably, one of the compromised hosts also previously hosted an administration panel for Coruna, an older iOS exploit kit, hinting at potential overlap or shared infrastructure with other threat groups, possibly including UNC6353, which has been linked to attacks on Ukrainian targets.
Further investigation by Censys uncovered an open directory listing in Frankfurt containing the operator's tooling. This included an SSH key comment referencing "jkcing@apt," a web-content fuzzer, and mentions of a previously undocumented malware family dubbed Thorn C2. The "C2 Control Panel" itself features a distinct visual design with a dark background, red accents, an animated particle effect, and a visible Telegram contact link for the "Asia-Pacific Group," providing a direct communication channel for the operator.