Home / Aug 04, 2026 / Story
0
#7 The Hacker News general August 03, 2026 at 10:49 UTC

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

By [email protected] (The Hacker News)

AI Summary

An unidentified Chinese threat actor is operating over 100 fake AWS sign-in pages while deploying the GHOSTBLADE implant on Apple iOS devices using a publicly leaked version of the DarkSword exploit kit, as identified by Censys's attack surface management platform. The campaign targets iOS users through credential-phishing infrastructure combined with browser-based exploitation. The use of a leaked commercial exploit kit lowers the barrier to sophisticated iOS targeting and complicates attribution.

Relevance score: 79.0/100

# More from August 04