🟠 High  |  Source: The Hacker News


A Chinese-speaking threat actor is targeting Apple iOS devices using a publicly leaked version of the DarkSword exploit kit to deploy malware known as GHOSTBLADE. The campaign involves over 100 fake AWS sign-in pages, suggesting credential harvesting alongside device exploitation. The use of a leaked kit lowers the barrier to entry for this type of attack, broadening the potential threat landscape.

Security Architect’s Take: Audit your organisation’s AWS sign-in flows and enforce phishing-resistant MFA (e.g. FIDO2/passkeys) to mitigate credential harvesting via fake login pages. Additionally, review mobile device management (MDM) policies to ensure iOS devices accessing corporate resources are patched and have web content filtering in place to block known malicious domains.

Original advisory: Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS