negativeSYS.SOURCE: The Hacker News• 2026-08-03T16:19:06+05:30
Chinese Threat Actor Leverages Leaked DarkSword Exploit Kit to Deploy GHOSTBLADE Malware on iOS Devices
A Chinese threat actor is using a leaked DarkSword exploit kit to target iOS devices, deploying GHOSTBLADE malware through fake AWS sign-in pages and watering hole attacks. The attack chain exploits patched vulnerabilities to steal credentials and exfiltrate data via compromised domains and admin panels.
An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.
Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit.
"
*** END OF TRANSMISSION ***