ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Mobile Security

Leaked DarkSword kit used to deliver GHOSTBLADE malware on iOS via fake AWS logins

Source headline: Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 1 hour ago

Intelligence Summary

A Chinese-linked threat actor is using a publicly leaked DarkSword exploit kit to target Apple iOS devices. The campaign relies on more than 100 web properties identified by Censys, many impersonating AWS sign-in pages. The malicious infrastructure also hosts the exploit toolkit on the same domain. Victims are at risk of having the GHOSTBLADE malware deployed through the exploit chain. Organizations should review exposure to suspicious login spoofing domains and harden iOS browsing and app access pathways.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#phishing #ios #darksword #exploit-kit #ghostblade #spoofed-aws-logins
Original reporting The Hacker News Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
Open original source