


Perceptive Security
SOC/SIEM Consultancy

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
Published:
3 augustus 2026 om 12:49:06
Alert date:
3 augustus 2026 om 13:00:35
Source:
thehackernews.com
Mobile & IoT, Ransomware & Malware, Zero-Day Vulnerabilities, Identity & Access, Data Breach & Exfiltration
An unknown Chinese threat actor has been observed targeting Apple iOS devices using a publicly leaked version of the DarkSword exploit kit. The campaign was identified by attack surface management platform Censys, which detected over 100 web properties operated by the threat actor. The majority of these properties consist of fake Amazon Web Services (AWS) sign-in pages, likely used for credential harvesting. These fraudulent pages are hosted on a domain that also serves the DarkSword exploit toolkit. The final payload delivered in this campaign is GHOSTBLADE, a malware targeting iOS devices. The use of a leaked exploit kit lowers the barrier for threat actors to conduct sophisticated mobile attacks. The campaign highlights growing threats against iOS devices from state-aligned or state-sponsored Chinese actors.
Technical details
An unknown Chinese threat actor is leveraging a publicly leaked version of the DarkSword full-chain iOS exploit kit to deploy GHOSTBLADE malware. The actor operates over 100 web properties, primarily fake AWS sign-in pages and Apple ID credential-harvesting decoys. The attack flow begins when a victim visits one of the operator's domains, which loads a malicious iframe that executes JavaScript triggering the DarkSword exploit chain. DarkSword targets iOS versions 18.4 through 18.7 and exploits now-patched vulnerabilities in Apple's mobile OS. Upon successful exploitation, GHOSTBLADE deploys modules to dump keychain data, iCloud credentials, and Wi-Fi credentials, then performs file exfiltration. Harvested data is packaged and transmitted to attacker-controlled endpoints. The operator manages three control panels: DarkSword Admin, Decode Dashboard, and C2 Control Panel. The C2 Control Panel displays Chinese text '亚太集团' ('Asia-Pacific Group') and includes a Telegram contact link. The kit used is the leaked original source code (not a reimplementation), evidenced by a shared staging-page hash and Russian-language code comments inherited from the leaked source. Infrastructure is primarily hosted in Hong Kong with additional presence in Japan, the US, Europe, and Singapore. An open directory listing in Frankfurt (93.152.221[.]37) exposes operator tooling including an SSH key comment 'jkcing@apt', a web-content fuzzer, and references to a previously undocumented malware family called 'Thorn C2'. The Singaporean host also hosted an administration panel for Coruna, another iOS exploit kit targeting iOS versions 3.0 through 17.2.1. Threat actor UNC6353 has been linked to use of both DarkSword and Coruna exploit kits in attacks against Ukrainian targets.
Mitigation steps:
1. Update Apple iOS devices to the latest available version beyond 18.7 to ensure all patched vulnerabilities exploited by DarkSword are remediated. 2. Avoid visiting suspicious or unknown websites, particularly those impersonating AWS console sign-in pages or Apple ID login pages. 3. Monitor network traffic for connections to the identified malicious IP addresses and block them at the firewall/proxy level. 4. Block the Telegram contact URL hxxps://t[.]me/YATA0000 if applicable. 5. Implement mobile device management (MDM) solutions to enforce security policies and detect unauthorized configuration changes on iOS devices. 6. Use threat intelligence platforms to monitor for indicators associated with DarkSword, GHOSTBLADE, Coruna, and Thorn C2 malware families. 7. Monitor for watering hole attacks by inspecting web content for malicious iframe injections loading JavaScript exploit chains. 8. Alert on keychain, iCloud credential, and Wi-Fi credential access anomalies on managed iOS devices. 9. Investigate any device connections to the listed C2 IP addresses, especially on ports 8888 and 3000. 10. Organizations with users in Saudi Arabia, Turkey, Malaysia, Ukraine, and Hong Kong should be particularly vigilant given historical targeting patterns.
Affected products:
Apple iOS 18.4
Apple iOS 18.5
Apple iOS 18.6
Apple iOS 18.7
Apple iOS 3.0 through 17.2.1 (Coruna exploit kit)
Related links:
https://censys.com/blog/darkswords-panel-sprawl/
https://thehackernews.com/2026/03/darksword-ios-exploit-kit-uses-6-flaws.html
https://thehackernews.com/2026/03/ta446-deploys-leaked-darksword-ios.html
https://github.com/ghh-jb/DarkSword
https://thehackernews.com/2026/03/coruna-ios-exploit-kit-uses-23-exploits.html
Related CVE's:
Related threat actors:
IOC's:
38.22.89[.]117:8888, 103.97.128[.]67:8888, 162.4.136[.]30:8888, 223.26.63[.]56:8888, 151.243.126[.]191:8888, 107.175.49[.]181:3000, 103.238.129[.]112:3000, 38.181.52[.]95, 103.106.190[.]217, 103.226.155[.]200, 103.226.155[.]201, 202.8.120[.]249, 93.152.221[.]37, hxxps://t[.]me/YATA0000, SSH key comment: jkcing@apt, Malware family: GHOSTBLADE, Malware family: Thorn C2, Exploit kit: DarkSword, Exploit kit: Coruna
This article was created with the assistance of AI technology by Perceptive.
