hacker-news · Crawled Aug 3, 2026

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

14 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

A Chinese threat actor is leveraging a publicly leaked version of the DarkSword exploit kit to target iOS devices running versions 18.4 through 18.7. The campaign uses fake AWS and Apple ID sign-in pages as watering holes to deliver the GHOSTBLADE information-stealing malware, which exfiltrates keychain, iCloud, and Wi-Fi credentials. The attacker infrastructure includes multiple malicious panels such as 'DarkSword Admin,' 'Decode Dashboard,' and 'C2 Control Panel,' with several IP addresses hosting these interfaces and a Telegram contact link recovered from one panel.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 14 extracted

Type Value Detail
IP 38[.]181[.]52[.]95 Details →
IP 103[.]106[.]190[.]217 Details →
IP 38[.]22[.]89[.]117 Details →
IP 103[.]97[.]128[.]67 Details →
IP 162[.]4[.]136[.]30 Details →
IP 223[.]26[.]63[.]56 Details →
IP 151[.]243[.]126[.]191 Details →
IP 107[.]175[.]49[.]181 Details →
IP 103[.]238[.]129[.]112 Details →
IP 103[.]226[.]155[.]200 Details →
IP 103[.]226[.]155[.]201 Details →
IP 202[.]8[.]120[.]249 Details →
IP 93[.]152[.]221[.]37 Details →
Domain t[.]me/YATA0000 Details →

MITRE ATT&CK TTPs 5 techniques