Chinese Threat Actor Utilizes Leaked DarkSword Kit to Target iOS Devices
A Chinese-speaking threat actor has been observed using a leaked version of the DarkSword exploit kit to target Apple iOS devices. The campaign involves over 100 web properties, including fake Amazon Web Services sign-in pages, to deploy GHOSTBLADE, an information-stealing malware. The DarkSword kit, which targets iOS versions 18.4 through 18.7, exploits vulnerabilities in Apple's mobile operating system to execute JavaScript and deploy the malware. The campaign has been linked to commercial surveillance vendors and suspected state-sponsored actors.