ShellCodeX Intelligence Brief
HIGH
Mobile Security
Leaked DarkSword kit used to deliver GHOSTBLADE malware on iOS via fake AWS logins
Source headline: Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
Threat level
High
Signal strength
75/100
Source confidence
1 source
Published
1 hour ago
Intelligence Summary
A Chinese-linked threat actor is using a publicly leaked DarkSword exploit kit to target Apple iOS devices. The campaign relies on more than 100 web properties identified by Censys, many impersonating AWS sign-in pages. The malicious infrastructure also hosts the exploit toolkit on the same domain. Victims are at risk of having the GHOSTBLADE malware deployed through the exploit chain. Organizations should review exposure to suspicious login spoofing domains and harden iOS browsing and app access pathways.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
The Hacker News
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
Open original source