SECURITYTHE HACKER NEWS
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
A Chinese threat actor is using a leaked DarkSword exploit kit to deploy GHOSTBLADE on Apple iOS devices. Censys identified over 100 web properties operated by the actor, primarily fake Amazon Web Services sign-in pages hosting the exploit toolkit.
Mentioned
Related Signal
Adjacent reporting
- Apple Breaks Precedent, Patches DarkSword for iOS 18
- Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
- Chinese attackers are pwning your infrastructure to use in attacks, 10 countries warn
- ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows
- China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan