Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
thehackernews.com Aug 3, 2026

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

AI-summarised brief · reviewed before publication

An unnamed Chinese-speaking threat actor has deployed the publicly leaked DarkSword exploit kit against Apple iOS devices, operating over 100 web properties that mimic AWS sign‑in and Apple ID pages. The kit targets iOS 18.4–18.7, using watering holes to trigger patched vulnerabilities, then delivers GHOSTBLADE malware that harvests keychain, iCloud, and Wi‑Fi credentials. The operator hosts multiple admin panels across Hong Kong, Singapore, Japan, the U.S., and Europe, with a Telegram contact revealed as a direct communication channel.

💡 Why It Matters

  • · The use of a leaked, full‑chain exploit kit demonstrates how quickly sophisticated malware can spread once source code is public, threatening millions of iOS users worldwide.