
Leaked DarkSword Kit Powers a Global iOS GHOSTBLADE Campaign
An unknown Chinese-speaking threat actor is using a publicly leaked DarkSword exploit kit to deploy GHOSTBLADE on iOS devices (versions 18.4–18.7) via watering-hole sites and fake sign-in portals. The attack chain loads JavaScript through malicious iframes to execute the kit, exfiltrating keychain, iCloud, and Wi‑Fi credentials to attacker-controlled endpoints. Multiple DarkSword admin panels are hosted across Hong Kong, Singapore, and other regions, with ties to other tools and groups, signaling expanded use of the kit since the leak (including indicators linked to UNC6353). The operation also references additional tooling and decoy pages, highlighting a broader, evolving threat landscape against iOS targets.

