A sophisticated Chinese threat actor has been using a leaked DarkSword exploit kit to deploy a notorious malware variant, GHOSTBLADE, on iOS devices. The attack vector targets iPhone and iPad users, compromising their sensitive data and potentially paving the way for further malicious activities.
The DarkSword exploit kit, initially designed to target Android devices, has been modified by the threat actor to take advantage of vulnerabilities in iOS’s kernel mode. This allows the malware to escape the sandbox environment and gain unauthorized access to device resources. GHOSTBLADE, a previously discovered piece of malware, is then deployed on compromised devices, giving attackers remote control over the victim’s phone or tablet.
The Chinese threat actor is believed to be utilizing leaked DarkSword code to deploy GHOSTBLADE, taking advantage of a vulnerability in Apple’s iOS operating system. This is not the first time a modified exploit kit has been used by threat actors; however, this particular combination poses significant risks due to its ability to bypass security measures and establish a persistent backdoor on compromised devices.
The attack pathway is complex but can be broken down into several key steps. First, the DarkSword exploit kit exploits a zero-day vulnerability in iOS’s kernel mode, allowing the malware to execute code with elevated privileges. This creates an opening for GHOSTBLADE to infect the device and establish communication with its command and control server. Once established, attackers can remotely access compromised devices, steal sensitive information, or use them as entry points for further attacks.
The scope of this attack is still unclear, but experts warn that it could be more widespread than initially thought. Given the sophistication of the DarkSword exploit kit and GHOSTBLADE malware, it’s possible that many users may have unknowingly fallen victim to this campaign.
To mitigate risks associated with this threat, we recommend that iOS users take immediate action by updating their device software to the latest version available. This ensures they’re protected against known vulnerabilities, including those targeted by the DarkSword exploit kit. Additionally, it’s crucial for users to exercise caution when opening attachments or clicking on links from unknown senders, as these are common tactics used by attackers to deliver malware payloads.
Source: The Hacker News — 2026-08-03