HackerFeeds

CyberSecurity News

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

The Hacker News
· August 3, 2026

AI summary

A Chinese threat actor has been identified using a leaked version of the DarkSword exploit kit to target Apple iOS devices. The actor is running a campaign that involves over 100 web properties, with most being fake Amazon Web Services sign-in pages. These fake pages are hosted on a domain that also contains the exploit toolkit, which is used to deploy GHOSTBLADE on iOS devices. The discovery was made by Censys, an attack surface management platform. The threat actor's use of the leaked DarkSword kit allows them to carry out their campaign against iOS devices.

Read the full article at The Hacker Newsthehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.