Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-04 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

Summary

An unknown Chinese-speaking threat actor is running a campaign targeting iOS devices using a publicly leaked version of the DarkSword exploit kit. Censys identified the actor running more than 100 web properties, mostly fake AWS sign-in pages on a domain hosting the exploit toolkit.

Details

Hosting concentrates in Hong Kong but reaches into Japan, the United States, and Europe. DarkSword is a full-chain exploit kit previously used by commercial surveillance vendors and suspected state-sponsored actors targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since November 2025.

Sources