Find notable cyber news and cases, enriched with sources, timelines, and signals.

GHOSTBLADE credential-stealing activity on Apple iOS

Malware Activity
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account takeover and deeper compromise. The activity uses a DarkSword exploit chain and malicious web pages to reach iOS 18.4 through 18.7 targets. Successful execution turns the implant into a credential-stealing and file-exfiltration tool. The operation expands the blast radius beyond the initial exploit by collecting reusable login material from compromised devices.

Related Happenings

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

CrashStealer macOS information stealer activity

Malware Activity
H score10 First: 13.07.2026 20:36 Last: 13.07.2026 20:36 Sources 1

About this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...

PromptSpy backdoor for Android with Gemini API automation

Malware Activity
H score22 First: 11.05.2026 16:02 Last: 11.05.2026 16:02 Sources 1

About this happening: The PromptSpy backdoor for Android was highlighted for using Gemini APIs to automate device interaction, increasing the risk of unauthorized control on infected phones...

DarkSword iPhone exploit chain exploitation wave

Exploitation Wave
H score89 First: 18.03.2026 23:15 Last: 18.03.2026 23:15 Sources 1

How related: DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.

About this happening: DarkSword is an iPhone exploitation wave against Apple iOS devices that now includes a publicly leaked exploit kit used by an unknown Chinese threat actor to r...

Latest development: 03.08.2026 13:49

An unknown Chinese threat actor ran more than 100 web properties impersonating AWS and Apple ID sign-in pages to deliver a leaked DarkSword exploit chain against Apple iOS devices and deploy GHOSTBLADE for credential theft and file exfiltration. Censys linked the DarkSword Admin panel to seven hosts across three countries as of July 30, 2026, with hosting concentrated in Hong Kong but reaching Japan, the United States, Europe, Singapore, and Frankfurt.

ZeroDayRAT mobile spyware targeting Android and iOS

Malware Activity
H score26 First: 10.02.2026 16:00 Last: 10.02.2026 16:00 Sources 1

About this happening: ZeroDayRAT is a newly documented mobile spyware operation targeting Android and iOS devices, creating broad risk for persistent surveillance and financial abuse. It ca...

Timeline

  1. 03.08.2026 13:49 2 articles · 1h ago

    Leaked DarkSword kit drives GHOSTBLADE credential theft on iOS

    Initial Disclosure

    An unknown Chinese-threat actor used a publicly leaked DarkSword exploit kit against Apple iOS devices, luring victims through fake AWS sign-in pages and Apple ID decoys before a malicious iframe loaded JavaScript that fired the exploit chain and deployed GHOSTBLADE. Censys said the operator ran more than 100 web properties, with hosting concentrated in Hong Kong and reaching Japan, the United States, and Europe, and that successful exploitation led to keychain, iCloud, and Wi‑Fi credential dumping followed by file exfiltration.

    Show sources