#7
The Hacker News
general
August 03, 2026 at 10:49 UTC
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
By [email protected] (The Hacker News)
AI Summary
An unidentified Chinese threat actor is operating over 100 fake AWS sign-in pages while deploying the GHOSTBLADE implant on Apple iOS devices using a publicly leaked version of the DarkSword exploit kit, as identified by Censys's attack surface management platform. The campaign targets iOS users through credential-phishing infrastructure combined with browser-based exploitation. The use of a leaked commercial exploit kit lowers the barrier to sophisticated iOS targeting and complicates attribution.
Relevance score: 79.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →