Tag

Ghostblade

All articles tagged with #ghostblade

Leaked DarkSword Kit Powers a Global iOS GHOSTBLADE Campaign
technology22 days ago

Leaked DarkSword Kit Powers a Global iOS GHOSTBLADE Campaign

An unknown Chinese-speaking threat actor is using a publicly leaked DarkSword exploit kit to deploy GHOSTBLADE on iOS devices (versions 18.4–18.7) via watering-hole sites and fake sign-in portals. The attack chain loads JavaScript through malicious iframes to execute the kit, exfiltrating keychain, iCloud, and Wi‑Fi credentials to attacker-controlled endpoints. Multiple DarkSword admin panels are hosted across Hong Kong, Singapore, and other regions, with ties to other tools and groups, signaling expanded use of the kit since the leak (including indicators linked to UNC6353). The operation also references additional tooling and decoy pages, highlighting a broader, evolving threat landscape against iOS targets.

TA446 Expands DarkSword iOS Attacks in Broad Spear-Phishing Campaign
cybersecurity5 months ago

TA446 Expands DarkSword iOS Attacks in Broad Spear-Phishing Campaign

TA446, a Russia-linked threat group, used the DarkSword iOS exploit kit in a targeted spear-phishing operation to deliver the GHOSTBLADE dataminer and the MAYBEROBOT backdoor via password-protected ZIPs; emails spoofed Atlantic Council discussion invites and redirected iPhone users (March 26, 2026) to the exploit kit through decoy PDFs, with server-side filtering guiding iOS browsers to the kit but no sandbox escapes observed. The campaign broadened targets to government, think tanks, higher education, finance, and legal entities, suggesting opportunistic credential harvesting and intel collection. Apple warns users with Lock Screen alerts and urges updates; a leaked DarkSword version on GitHub could democratize the exploit, potentially expanding mobile threats, per researchers.

Patch now: DarkSword toolkit pushes urgent iPhone update
technology5 months ago

Patch now: DarkSword toolkit pushes urgent iPhone update

Apple urges iPhone users to update to iOS 26.3+ after the DarkSword hacking toolkit appeared on GitHub, enabling JavaScript-based malware (Ghostblade, Ghostknife) that can steal data, record audio, or reveal location on devices running iOS 18.4–18.7; vulnerabilities are fixed by 26.3 (and 26.3.1), and up-to-date devices are not vulnerable. Update via Settings > General > Software Update, or use Background Security Improvements for immediate patches; GTIG notes the toolkit has been used to target regions including Malaysia, Saudi Arabia, Turkey, and Ukraine.