Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

Summary

An unknown Chinese threat actor is targeting Apple iOS devices by using a publicly leaked version of the DarkSword exploit kit. The threat actor is operating over 100 web properties, many of which are fake AWS sign-in pages, hosting the exploit toolkit.

IFF Assessment

FOE

This article details a new campaign by a threat actor leveraging an exploit kit, posing a direct threat to defenders.

Defender Context

Defenders should be aware of threat actors utilizing leaked exploit kits, particularly targeting mobile devices like iOS. Phishing attempts masquerading as legitimate cloud service logins, such as fake AWS pages, are a common tactic used to distribute such kits.

Read Full Story →