Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

chinese-threat-actor-uses-leaked-darksword-kit-to-deploy-ghostblade-on-ios
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

Ravie LakshmananAug 03, 2026Mobile Security / Vulnerability

An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.

Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit.

“The hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe,” Censys researcher Aidan Holland said in an analysis published on July 31, 2026.

DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.

The kit, which specifically targets iOS versions 18.4 through 18.7, has been observed to employ watering holes as a starting point to trigger now-patched vulnerabilities in Apple’s mobile operating system to execute JavaScript that ultimately facilitates the deployment of GHOSTBLADE, an information-stealing malware.

The use of DarkSword has since expanded in scope following a public leak of its source code, prompting other threat actors to join the exploitation bandwagon.

The latest findings from Censys show that the login page for a panel called “DarkSword Admin” matches seven hosts across three countries as of July 30, 2026, in addition to a Singapore-based host (“38.181.52[.]95”) running three distinct exploit-panel front ends and a Hong Kong host that bundles an Apple ID credential-harvesting decoy (“103.106.190[.]217”).

One such login panel served on the IP address “38.22.89[.]117:8888” contains Chinese-language field labels for “username,” “password,” and “Log in.” The other six IP addresses are below –

  • 103.97.128[.]67:8888
  • 162.4.136[.]30:8888
  • 223.26.63[.]56:8888
  • 151.243.126[.]191:8888
  • 107.175.49[.]181:3000
  • 103.238.129[.]112:3000

The attack flow is fairly consistent in that it begins when a victim reaches one of the operator’s domains – an AWS-console impersonation subdomain or an Apple ID sign-in page – causing a malicious iframe element to load JavaScript that fires the DarkSword chain and finally deploys GHOSTBLADE modules.

On successful exploitation, the implant delivers keychain, iCloud, and Wi-Fi credential-dumping modules and commences the file-exfiltration sweep. The harvested data is then packaged and transmitted to attacker-controlled endpoints. The attacker then logs in to one of the panels, namely DarkSword Admin, Decode Dashboard, or C2 Control Panel, to extract the pilfered data.

The IP addresses associated with the two other login panels are as follows –

  • 103.226.155[.]200 (Decode Dashboard)
  • 103.226.155[.]201 (Decode Dashboard)
  • 202.8.120[.]249 (Decode Dashboard)
  • 103.106.190[.]217 (C2 Control Panel), which also co-hosts the Apple ID decoy sign-in page

“This cluster runs the leaked kit rather than a reimplementation, and the evidence is a shared staging-page hash plus Russian-language code comments carried over from the leaked source,” Holland said.

What’s more, the Singaporean host (now no longer active) has been found to host an administration panel for Coruna, another iOS exploit kit that predates DarkSword and goes after iOS versions 3.0 through 17.2.1. There is some evidence to suggest that a threat actor known as UNC6353 has leveraged both exploit kits in its attacks aimed at Ukrainian targets.

Censys said it also discovered an open directory listing in Frankfurt (“93.152.221[.]37”) that exposes the operator’s tooling, including an SSH key comment “jkcing@apt,” a web-content fuzzer, and references to a previously undocumented malware family referred to as Thorn C2.”

“The ‘C2 Control Panel’ login itself is a visually distinct build from the other two panels: a near-black #06060d background, a #ff0050 red accent, an animated particle-canvas effect, a group name rendered directly on the page (亚太集团, ‘Asia-Pacific Group’), and a visible Telegram contact link, hxxps://t[.]me/YATA0000,” it noted. “That’s the first direct contact channel we’ve recovered for this operator; the other panels give us a login gate and nothing else.”

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Leave a Reply

Your email address will not be published. Required fields are marked *