The record
Written from the 1 report below. Nothing here is unsourced.
- An unknown Chinese-speaking threat actor is using a leaked iOS exploit kit called DarkSword to deploy GHOSTBLADE, an information-stealing malware, on Apple iPhones running iOS versions 18.4 through 18.7.
- Censys researchers found over 100 web properties tied to the actor, mostly fake AWS sign-in pages, with hosting concentrated in Hong Kong and extending to Japan, the US, and Europe.
- The attacks start when victims visit these fake pages, triggering the exploit chain that then steals keychain, iCloud, and Wi-Fi credentials and exfiltrates files to attacker-controlled servers.
- The campaign shows how a public leak of the DarkSword source code has allowed new actors to adopt the previously restricted surveillance-grade tooling.
What to watch next
- Whether the Telegram contact link t.me/YATA0000, the first direct channel recovered for this operator, leads to identifying the actor
- The previously undocumented 'Thorn C2' malware family exposed via the Frankfurt open directory
- Further spread of the leaked DarkSword kit to additional threat actors beyond this cluster
Coverage1
1 report
English national1
All filed from India
Named China · Japan · United States · Singapore · Germany · Apple · Aidan Holland · Amazon Web Services · Asia-Pacific Group · Censys · Coruna · DarkSword · GHOSTBLADE · Google Threat Intelligence Group · iVerify · Lookout · Thorn C2
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
