Chinese Threat Actor Deploys GHOSTBLADE via Leaked DarkSword iOS Kit
A previously unknown Chinese threat actor has been observed leveraging a publicly leaked version of the DarkSword exploit kit to target Apple iOS devices in a campaign identified by attack surface management platform Censys. The actor controls more than 100 web properties, most of which impersonate Amazon Web Services (AWS) sign-in pages, hosted primarily in Hong Kong with additional infrastructure spanning Japan, the United States, Singapore, and Europe. Researchers tied the operation to Chinese-language login panels and found that one IP address ("38.22.89[.]117:8888") contains Mandarin field labels for username, password, and log-in, strongly suggesting the threat actor's origin.
DarkSword, originally documented earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, is a full-chain exploit kit that specifically targets iOS versions 18.4 through 18.7. It has previously been attributed to commercial surveillance vendors and suspected state-sponsored actors conducting campaigns against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025. The kit initiates attacks through watering holes, where victims are lured to AWS-console impersonation subdomains or Apple ID sign-in pages. A malicious iframe loads JavaScript that triggers the DarkSword exploit chain, ultimately deploying GHOSTBLADE, a modular information-stealing implant. Security professionals investigating suspicious domains associated with this campaign can use a WHOIS lookup or DNS leak test to verify hosting provenance.
Once GHOSTBLADE achieves execution on the compromised device, it deploys dedicated modules to harvest keychain entries, iCloud credentials, and Wi-Fi passwords before initiating a broader file-exfiltration sweep. The stolen data is packaged and transmitted to attacker-controlled endpoints, after which the operator accesses one of three back-end panels (DarkSword Admin, Decode Dashboard, or C2 Control Panel) to retrieve the pilfered information. Censys identified seven hosts across three countries running the DarkSword Admin login panel as of July 30, 2026, including a Singapore-based server ("38.181.52[.]95") hosting three distinct exploit-panel front ends and a Hong Kong host ("103.106.190[.]217") that bundles an Apple ID credential-harvesting decoy. The associated login panel IP addresses were 103.97.128[.]67:8888, 162.4.136[.]30:8888, 223.26.63[.]56:8888, 151.243.126[.]191:8888, 107.175.49[.]181:3000, and 103.238.129[.]112:3000, with the Decode Dashboard tied to 103.226.155[.]200 and 103.226.155[.]201, and the C2 Control Panel at 202.8.120[.]249.
The public leak of DarkSword's source code has significantly expanded its reach, lowering the barrier for additional threat actors to join the exploitation bandwagon. With GHOSTBLADE now in the hands of multiple groups actively harvesting Apple ID credentials and iCloud data, users should be vigilant about where they enter their Apple credentials. Run a email breach checker to confirm whether your Apple ID or associated email has appeared in any known leaks, audit your stored passwords with a password checker, and enable two-factor authentication on your Apple account to limit the impact of credential theft. Defenders are also advised to scan their networks for traffic to the published infrastructure using a port scanner and to verify any suspicious hosting with a privacy checkup to identify potential exposure.