[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWr7j8Fb-9vqdgOV6GE995BN3PrZvxzBVkCD0wt5H4K4":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"4dae81eb-4b41-4c24-adad-bf1c9992e9c5","leaked-exploit-kit-targets-unpatched-ios-devices-to-deploy-ghostblade-infostealer","03c54fde-e039-42f9-b419-6fed8e339aaf","Leaked Exploit Kit Targets Unpatched iOS Devices to Deploy GHOSTBLADE Infostealer","A Chinese threat actor is leveraging a leaked version of the DarkSword exploit kit to compromise iOS devices through vulnerabilities that Apple has since patched, meaning victims running outdated software remain exposed. The campaign uses over 100 convincing fake AWS sign-in pages to lure targets, demonstrating how social engineering and technical exploitation are combined for maximum impact. The deployed GHOSTBLADE malware silently exfiltrates credentials and sensitive data, making delayed patching directly responsible for potential data loss. This highlights that even patched vulnerabilities remain dangerous at scale when device owners and organizations fail to apply updates promptly.","**Immediate actions:**\n- Update all iOS devices to the latest available version to close the vulnerabilities exploited by the DarkSword kit.\n- Educate users to verify the authenticity of AWS and other cloud sign-in pages before entering credentials, particularly when navigating from links or ads.\n- Deploy Mobile Device Management (MDM) solutions to enforce minimum OS version requirements across organizational devices.\n\n**Long-term improvements:**\n- Establish a formal mobile patch management policy that mandates OS updates within a defined SLA (e.g., 72 hours for critical patches).\n- Maintain an up-to-date inventory of all mobile endpoints and their OS versions to identify unpatched devices quickly.\n- Implement phishing-resistant MFA (e.g., FIDO2\u002Fpasskeys) on all cloud services, including AWS, to reduce credential theft impact.\n\n**Detection measures:**\n- Monitor DNS and proxy logs for connections to known DarkSword or GHOSTBLADE infrastructure indicators of compromise (IoCs).\n- Deploy Endpoint Detection and Response (EDR) or Mobile Threat Defense (MTD) solutions to detect anomalous data exfiltration from iOS devices.\n- Subscribe to threat intelligence feeds that track leaked exploit kits and update blocklists accordingly.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 9: Email and Web Browser Protections","NIST SP 800-40: Guide to Enterprise Patch Management","NIST SI-2: Flaw Remediation","NIST SC-18: Mobile Code","NIST AC-17: Remote Access","GDPR Article 32: Security of Processing","Apple Platform Security Guide: iOS Update Management","NIST CSF ID.RA-1: Asset Vulnerabilities Identified","published","2026-08-03T12:21:15.652333+00:00","2026-08-03T12:21:15.543+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fchinese-threat-actor-uses-leaked.html","chinese-threat-actor-uses-leaked-darksword-kit-to-deploy-ghostblade-on-ios-8f03bf","Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]