A fresh threat actor, identified by security researchers, has been observed targeting Apple iOS devices with a sophisticated campaign that exploits a publicly leaked version of the DarkSword exploit kit.
The actor, which speaks Chinese, has deployed more than 100 malicious web properties that serve as the front end for the attack.
Most of the properties are designed to look like Amazon Web Services sign‑in pages, a tactic that aims to lull users into trusting the site and entering credentials.
In addition to the phishing façade, the domain also hosts the actual exploit code that delivers the payload.
The payload, known as GHOSTBLADE, is a new variant that targets iOS by taking advantage of a zero‑day vulnerability in the operating system’s networking stack.
Once the exploit is executed, GHOSTBLADE installs a backdoor that allows the threat actor to exfiltrate data and maintain persistence on the device.
Security researchers using the attack surface management platform Censys were the first to map out the actor’s infrastructure and the scale of the operation.
Censys identified that the actor’s web properties are distributed across multiple subdomains, with the majority redirecting to the fake AWS sign‑in pages.
The use of a leaked DarkSword kit demonstrates the actor’s ability to repurpose existing tools for new objectives, a trend that has been observed in other campaigns.
Apple’s iOS remains a high‑profile target for threat actors, and the emergence of GHOSTBLADE underscores the need for continued vigilance and timely patching.