Utopia Tech
SecurityAI-assisted1 min read

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

A Chinese threat actor is conducting a campaign against Apple iOS devices using a leaked version of the DarkSword exploit kit to deploy GHOSTBLADE malware. The attacker operates over 100 web properties, primarily fake AWS sign-in pages, hosted on domains that also contain the exploit toolkit, as identified by Censys.

UT

Utopia Tech

August 3, 2026 · 1 min read

Share

An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit. "

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content