Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unidentified Chinese threat actor has been seen using a publicly released version of the DarkSword exploit kit to launch a campaign against Apple iOS devices.
The threat actor was found to be operating over 100 web sites, the majority of which are phony Amazon Web Services (AWS) sign-in pages on a domain that also houses the exploit toolkit, according to attack surface management platform Censys.
According to a July 31, 2026, investigation by Censys analyst Aidan Holland, the hosting is concentrated in Hong Kong but extends to Japan, the US, and Europe.
DarkSword is a full-chain exploit kit that was found and described earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout. It is thought that commercial surveillance vendors and suspected state-spons...

