Executive Summary
- •Censys found the operator running over 100 fake Amazon Web Services sign-in pages to trigger the initial exploit chain.
- •The campaign targets iOS versions 18.4 through 18.7, deploying GHOSTBLADE malware to explicitly steal keychain, iCloud, and Wi-Fi credentials.
- •The backend infrastructure spans Hong Kong, Singapore, and Frankfurt, exposing clear connections to an older Coruna iOS exploit kit and a newly discovered Thorn C2 malware family.
Community Sentiment
Key Developments & Data
A Chinese threat actor deploys the leaked DarkSword kit against Apple $AAPL iOS devices.
Censys found the operator running over 100 fake Amazon Web Services sign-in pages to trigger the initial exploit chain.
The campaign targets iOS versions 18.4 through 18.7, deploying GHOSTBLADE malware to explicitly steal keychain, iCloud, and Wi-Fi credentials.
The backend infrastructure spans Hong Kong, Singapore, and Frankfurt, exposing clear connections to an older Coruna iOS exploit kit and a newly discovered Thorn C2 malware family.
"This cluster runs the leaked kit rather than a reimplementation, and the evidence is a shared staging-page hash plus Russian-language code comments carried over from the leaked source." — Aidan Holland
Zubiqo Intelligence Briefing
Get the unfiltered signal before markets open.
Top tech breakthroughs, venture funding, and market moves—synthesized into a 2-minute morning read. Zero PR fluff.
✓ 100% Free•✓ 1-click unsubscribe•✓ No spam ever




