hacker-news · Crawled Aug 3, 2026
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
14 IoCs 1 Actors 1 Malware
Read original article ↗
AI Summary
A Chinese threat actor is leveraging a publicly leaked version of the DarkSword exploit kit to target iOS devices running versions 18.4 through 18.7. The campaign uses fake AWS and Apple ID sign-in pages as watering holes to deliver the GHOSTBLADE information-stealing malware, which exfiltrates keychain, iCloud, and Wi-Fi credentials. The attacker infrastructure includes multiple malicious panels such as 'DarkSword Admin,' 'Decode Dashboard,' and 'C2 Control Panel,' with several IP addresses hosting these interfaces and a Telegram contact link recovered from one panel.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 14 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 38[.]181[.]52[.]95 | Details → |
| IP | 103[.]106[.]190[.]217 | Details → |
| IP | 38[.]22[.]89[.]117 | Details → |
| IP | 103[.]97[.]128[.]67 | Details → |
| IP | 162[.]4[.]136[.]30 | Details → |
| IP | 223[.]26[.]63[.]56 | Details → |
| IP | 151[.]243[.]126[.]191 | Details → |
| IP | 107[.]175[.]49[.]181 | Details → |
| IP | 103[.]238[.]129[.]112 | Details → |
| IP | 103[.]226[.]155[.]200 | Details → |
| IP | 103[.]226[.]155[.]201 | Details → |
| IP | 202[.]8[.]120[.]249 | Details → |
| IP | 93[.]152[.]221[.]37 | Details → |
| Domain | t[.]me/YATA0000 | Details → |