Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
A Chinese threat actor is leveraging a publicly leaked version of the DarkSword full-chain iOS exploit kit to deploy GHOSTBLADE, an information-stealing malware targeting iOS versions 18.4 through 18.7 The campaign operates over 100 web properties, predominantly fake AWS sign-in pages, with hosting concentrated in Hong Kong but extending to Japan, the US, and Europe DarkSword's source code leak has broadened its attack surface, enabling new actors to adopt the toolkit rather than reimplement it
Analysis
TL;DR
- A Chinese threat actor is leveraging a publicly leaked version of the DarkSword full-chain iOS exploit kit to deploy GHOSTBLADE, an information-stealing malware targeting iOS versions 18.4 through 18.7
- The campaign operates over 100 web properties, predominantly fake AWS sign-in pages, with hosting concentrated in Hong Kong but extending to Japan, the US, and Europe
- DarkSword's source code leak has broadened its attack surface, enabling new actors to adopt the toolkit rather than reimplement it from scratch
- The attack chain uses watering holes with malicious iframes triggering JavaScript exploits that deploy GHOSTBLADE modules to dump keychain, iCloud, Wi-Fi credentials, and exfiltrate files
- Censys identified direct operator contact via a Telegram link (t.me/YATA0000), a group name "Asia-Pacific Group" (亚太集团), and references to an undocumented malware family called Thorn C2
Why It Matters
The public leak of DarkSword's source code demonstrates how proprietary exploit toolkits, once exposed, can rapidly proliferate beyond their original operators and be adopted by diverse threat actors with varying capabilities. This case underscores the critical importance of patch management for iOS devices, as the campaign exploits now-patched vulnerabilities in Apple's mobile operating system to achieve remote code execution and credential theft.
Technical Details
- DarkSword Exploit Kit: A full-chain exploit kit targeting iOS 18.4–18.7 that uses watering hole attacks to trigger now-patched vulnerabilities, executing JavaScript that deploys the GHOSTBLADE information-stealing implant
- GHOSTBLADE Capabilities: Delivers modules for keychain, iCloud, and Wi-Fi credential dumping, followed by a file-exfiltration sweep; harvested data is transmitted to attacker-controlled endpoints
- Infrastructure: Over 100 web properties across multiple countries, including three distinct admin panels (DarkSword Admin, Decode Dashboard, C2 Control Panel) hosted on IPs in Hong Kong, Singapore, and other locations
- Attack Flow: Victim reaches a phishing domain (fake AWS console or Apple ID sign-in) → malicious iframe loads JavaScript → DarkSword exploit chain executes → GHOSTBLADE deploys → credentials and files are exfiltrated to C2 panels
- Associated Artifacts: SSH key comment "jkcing@apt," web-content fuzzer tools, references to Thorn C2 malware family, and a shared staging-page hash with Russian-language code comments linking operators to the leaked source
Industry Insight
The DarkSword leak illustrates the compounding risk of exploit kit proliferation: once source code is public, attribution becomes harder and the barrier to entry for iOS exploitation drops significantly, enabling less sophisticated actors to conduct high-quality attacks. Organizations should prioritize immediate patching of iOS 18.4–18.7 vulnerabilities and monitor for phishing infrastructure impersonating AWS and Apple services. The discovery of the Telegram contact and "Asia-Pacific Group" branding provides a concrete indicator for threat intelligence sharing and potential takedown coordination.
Disclaimer: The above content is generated by AI and is for reference only.