Leaked DarkSword Kit Deploys GHOSTBLADE Stealer on iOS Devices

Censys found a Chinese-speaking actor using the leaked DarkSword exploit kit to deploy the GHOSTBLADE info-stealer on iOS devices and steal credentials.
Table of Contents
    Add a header to begin generating the table of contents

    An unknown Chinese-speaking threat actor is using a publicly leaked version of the DarkSword exploit kit to target Apple iOS devices, according to an analysis by Censys. The campaign runs more than 100 web properties, most of them fake Amazon Web Services sign-in pages on a domain that also hosts the exploit toolkit, with hosting concentrated in Hong Kong and reach into Japan, the United States, and Europe.

    The attack chain delivers GHOSTBLADE, an information-stealing implant that dumps keychain, iCloud, and Wi-Fi credentials and exfiltrates files to attacker-controlled endpoints. The exploitation relies on iOS flaws that have since been patched, but the disclosure shows the leaked kit still runs against unpatched devices.

    How the DarkSword Kit and GHOSTBLADE Chain Work Together

    A victim who lands on a spoofed AWS console page or a lookalike Apple ID sign-in page gets a malicious iframe that loads JavaScript and fires the DarkSword exploit chain, which installs GHOSTBLADE. Operators then log into one of three panels — DarkSword Admin, Decode Dashboard, or the C2 Control Panel — to retrieve the stolen data. Censys found the cluster is running the leaked kit rather than a reimplementation, evidenced by a shared staging-page hash and Russian-language code comments carried over from the leaked source.

    The Asia-Pacific Group Panel and a First Operator Contact Channel

    The C2 Control Panel login displays the group name “亚太集团” (Asia-Pacific Group) alongside a Telegram contact link, which Censys described as the first direct contact channel recovered for the operator. In a separate finding, an open directory in Frankfurt exposed operator tooling including an SSH key comment reading “jkcing@apt,” a web-content fuzzer, and references to an undocumented malware family called Thorn C2.

    DarkSword’s Path From Surveillance Vendors to the Broader Ecosystem

    DarkSword was discovered earlier this year by Google Threat Intelligence Group, iVerify, and Lookout as a full-chain exploit kit targeting iOS 18.4 through 18.7. It was previously linked to commercial surveillance vendors and suspected state-sponsored actors operating against Saudi Arabia, Turkey, Malaysia, and Ukraine. Its adoption expanded after a public leak of its source code, and Censys found evidence the operator pattern extends to an older iOS exploit kit: a Singapore host previously ran an admin panel for Coruna, which targets iOS 3.0 through 17.2.1, and there is some evidence threat actor UNC6353 has used both kits against Ukrainian targets.

    Patching iOS 18.4–18.7 Devices Against the DarkSword Chain

    The campaign exploits now-patched iOS vulnerabilities, and Censys and its partners recommend keeping devices updated and avoiding entering credentials on lookalike AWS and Apple sign-in pages. Censys published indicators of compromise including panel IP addresses and domains. Before publishing its findings, Censys mapped DarkSword Admin login panels across seven hosts in three countries, evidence that the operator runs the panel infrastructure across a distributed footprint rather than a single server. For users, the practical mitigation is straightforward: keep the device updated, since the chain depends on now-patched flaws, and treat any login page reached through an unfamiliar link as suspect.

    The leak-driven spread of DarkSword follows a familiar trajectory in the mobile surveillance market: a capability once confined to well-funded commercial vendors and state programs becomes a commodity once its source is public. For defenders, the meaningful change is not the exploit itself but who can now deploy it — the panel infrastructure, the Telegram channel, and the operator tooling all point to a sustained, multi-domain operation rather than a one-off attack. The GHOSTBLADE payload’s focus on keychain and iCloud credentials also reflects a broader pattern in which mobile implants increasingly target the credential stores that unlock cloud and enterprise accounts, making a compromised phone a staging point for larger account takeovers.

    Related Posts