AI Security AI安全 18h ago Updated 15h ago 更新于 15小时前 41

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS 中国威胁行为者利用泄露的DarkSword工具包在iOS上部署GHOSTBLADE

A Chinese threat actor is leveraging a publicly leaked version of the DarkSword full-chain iOS exploit kit to deploy GHOSTBLADE, an information-stealing malware targeting iOS versions 18.4 through 18.7 The campaign operates over 100 web properties, predominantly fake AWS sign-in pages, with hosting concentrated in Hong Kong but extending to Japan, the US, and Europe DarkSword's source code leak has broadened its attack surface, enabling new actors to adopt the toolkit rather than reimplement it 中国威胁行为者利用泄露的DarkSword漏洞利用工具包针对iOS设备发起攻击,运营超过100个虚假AWS登录页面 DarkSword针对iOS 18.4-18.7版本,通过钓鱼页面触发已修复漏洞执行JavaScript,最终部署GHOSTBLADE信息窃取恶意软件 攻击者使用三个控制面板(DarkSword Admin、Decode Dashboard、C2 Control Panel)收集被盗数据,C2面板显示"亚太集团"名称和Telegram联系方式 攻击基础设施主要集中在香港,延伸至日本、美国和欧洲,SSH密钥注释"jkcing@apt"暴露了APT关联线索 泄露的源代码导致攻击工具扩

62
Hot 热度
58
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • A Chinese threat actor is leveraging a publicly leaked version of the DarkSword full-chain iOS exploit kit to deploy GHOSTBLADE, an information-stealing malware targeting iOS versions 18.4 through 18.7
  • The campaign operates over 100 web properties, predominantly fake AWS sign-in pages, with hosting concentrated in Hong Kong but extending to Japan, the US, and Europe
  • DarkSword's source code leak has broadened its attack surface, enabling new actors to adopt the toolkit rather than reimplement it from scratch
  • The attack chain uses watering holes with malicious iframes triggering JavaScript exploits that deploy GHOSTBLADE modules to dump keychain, iCloud, Wi-Fi credentials, and exfiltrate files
  • Censys identified direct operator contact via a Telegram link (t.me/YATA0000), a group name "Asia-Pacific Group" (亚太集团), and references to an undocumented malware family called Thorn C2

Why It Matters

The public leak of DarkSword's source code demonstrates how proprietary exploit toolkits, once exposed, can rapidly proliferate beyond their original operators and be adopted by diverse threat actors with varying capabilities. This case underscores the critical importance of patch management for iOS devices, as the campaign exploits now-patched vulnerabilities in Apple's mobile operating system to achieve remote code execution and credential theft.

Technical Details

  • DarkSword Exploit Kit: A full-chain exploit kit targeting iOS 18.4–18.7 that uses watering hole attacks to trigger now-patched vulnerabilities, executing JavaScript that deploys the GHOSTBLADE information-stealing implant
  • GHOSTBLADE Capabilities: Delivers modules for keychain, iCloud, and Wi-Fi credential dumping, followed by a file-exfiltration sweep; harvested data is transmitted to attacker-controlled endpoints
  • Infrastructure: Over 100 web properties across multiple countries, including three distinct admin panels (DarkSword Admin, Decode Dashboard, C2 Control Panel) hosted on IPs in Hong Kong, Singapore, and other locations
  • Attack Flow: Victim reaches a phishing domain (fake AWS console or Apple ID sign-in) → malicious iframe loads JavaScript → DarkSword exploit chain executes → GHOSTBLADE deploys → credentials and files are exfiltrated to C2 panels
  • Associated Artifacts: SSH key comment "jkcing@apt," web-content fuzzer tools, references to Thorn C2 malware family, and a shared staging-page hash with Russian-language code comments linking operators to the leaked source

Industry Insight

The DarkSword leak illustrates the compounding risk of exploit kit proliferation: once source code is public, attribution becomes harder and the barrier to entry for iOS exploitation drops significantly, enabling less sophisticated actors to conduct high-quality attacks. Organizations should prioritize immediate patching of iOS 18.4–18.7 vulnerabilities and monitor for phishing infrastructure impersonating AWS and Apple services. The discovery of the Telegram contact and "Asia-Pacific Group" branding provides a concrete indicator for threat intelligence sharing and potential takedown coordination.

TL;DR

  • 中国威胁行为者利用泄露的DarkSword漏洞利用工具包针对iOS设备发起攻击,运营超过100个虚假AWS登录页面
  • DarkSword针对iOS 18.4-18.7版本,通过钓鱼页面触发已修复漏洞执行JavaScript,最终部署GHOSTBLADE信息窃取恶意软件
  • 攻击者使用三个控制面板(DarkSword Admin、Decode Dashboard、C2 Control Panel)收集被盗数据,C2面板显示"亚太集团"名称和Telegram联系方式
  • 攻击基础设施主要集中在香港,延伸至日本、美国和欧洲,SSH密钥注释"jkcing@apt"暴露了APT关联线索
  • 泄露的源代码导致攻击工具扩散,同一攻击者还托管了另一iOS漏洞利用工具Coruna的管理面板

为什么值得看

本文揭示了国家级漏洞利用工具泄露后如何被非国家行为者利用,展示了高级攻击能力扩散的现实风险。对于移动安全从业者和企业IT部门而言,了解此类攻击链有助于加强iOS设备防护和钓鱼攻击防范意识。

技术解析

  • DarkSword漏洞利用工具包:全链条iOS漏洞利用工具,针对iOS 18.4-18.7版本,通过watering hole攻击方式触发已修复的Apple OS漏洞,执行JavaScript最终部署GHOSTBLADE恶意软件
  • 攻击流程:受害者访问伪造的AWS控制台或Apple ID登录页面 → 加载恶意iframe → 执行DarkSword漏洞利用链 → 部署GHOSTBLADE模块 → 窃取Keychain、iCloud和Wi-Fi凭据 → 数据打包传输至攻击者控制的基础设施
  • 控制面板架构:DarkSword Admin(7个主机跨3国)、Decode Dashboard(3个IP)、C2 Control Panel(1个IP),C2面板具有独特视觉设计(黑色背景#06060d、红色强调#ff0050、粒子动画效果),并直接显示Telegram联系方式
  • 攻击者基础设施:香港为主要托管地,新加坡、日本、美国、欧洲均有分布;发现SSH密钥注释"jkcing@apt"、Web内容fuzzer工具,以及未记录的Thorn C2恶意软件家族
  • 工具关联证据:共享的staging页面哈希值和源代码中的俄语注释表明攻击者使用的是泄露原版而非重新实现;同一攻击者还托管了Coruna(针对iOS 3.0-17.2.1)的管理面板

行业启示

  • 漏洞利用工具泄露风险加剧:国家级工具一旦泄露,将显著扩大攻击面,企业需加强对移动设备漏洞的及时修补和威胁情报监控
  • 移动设备成为高级攻击目标:iOS设备因用户价值高、安全防护相对薄弱而成为重点目标,组织应实施移动设备管理(MDM)策略并启用多因素认证
  • 钓鱼攻击与漏洞利用结合趋势:攻击者将社会工程学(伪造登录页面)与零日/已修复漏洞利用结合,需要加强员工安全意识培训和安全技术防护的双重建设

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究