Tag

Ghostblade

All articles tagged with #ghostblade

TA446 Expands DarkSword iOS Attacks in Broad Spear-Phishing Campaign
cybersecurity13 days ago

TA446 Expands DarkSword iOS Attacks in Broad Spear-Phishing Campaign

TA446, a Russia-linked threat group, used the DarkSword iOS exploit kit in a targeted spear-phishing operation to deliver the GHOSTBLADE dataminer and the MAYBEROBOT backdoor via password-protected ZIPs; emails spoofed Atlantic Council discussion invites and redirected iPhone users (March 26, 2026) to the exploit kit through decoy PDFs, with server-side filtering guiding iOS browsers to the kit but no sandbox escapes observed. The campaign broadened targets to government, think tanks, higher education, finance, and legal entities, suggesting opportunistic credential harvesting and intel collection. Apple warns users with Lock Screen alerts and urges updates; a leaked DarkSword version on GitHub could democratize the exploit, potentially expanding mobile threats, per researchers.

Patch now: DarkSword toolkit pushes urgent iPhone update
technology16 days ago

Patch now: DarkSword toolkit pushes urgent iPhone update

Apple urges iPhone users to update to iOS 26.3+ after the DarkSword hacking toolkit appeared on GitHub, enabling JavaScript-based malware (Ghostblade, Ghostknife) that can steal data, record audio, or reveal location on devices running iOS 18.4–18.7; vulnerabilities are fixed by 26.3 (and 26.3.1), and up-to-date devices are not vulnerable. Update via Settings > General > Software Update, or use Background Security Improvements for immediate patches; GTIG notes the toolkit has been used to target regions including Malaysia, Saudi Arabia, Turkey, and Ukraine.