Leaked DarkSword Toolkit Used to Spread GHOSTBLADE Malware Targeting iOS Devices

Leaked DarkSword Toolkit Used to Spread GHOSTBLADE Malware Targeting iOS Devices

A Chinese threat actor is exploiting a leaked version of the DarkSword kit to deploy GHOSTBLADE, a new iOS malware, emphasizing the need for website owners to secure their sites against malicious code injection.

Security researchers have identified an active campaign using a leaked version of the DarkSword exploitation framework to distribute GHOSTBLADE, a previously unknown iOS malware. The threat actor, attributed to China, is compromising legitimate websites to redirect visitors to malicious infrastructure that delivers the spyware payload to iPhone and iPad users. This development underscores the ongoing risk of website compromises serving as a springboard for broader cyberattacks.

Originally created for legitimate security testing, the DarkSword kit includes exploits targeting browser and operating system vulnerabilities. After its source code became publicly available, it was quickly weaponized by adversaries. In this operation, attackers inject obfuscated JavaScript into vulnerable sites, which then fingerprint visitors’ devices. When an iOS device is detected, the script loads GHOSTBLADE, often through a deceptive pop-up urging the user to install a configuration profile or via a silent WebKit exploit. Once installed, the malware can capture messages, contacts, account credentials, and other sensitive information from the device.

For website owners and hosting providers, the infection chain frequently begins with a compromised content management system—most notably outdated WordPress or Joomla installations. Attackers exploit weak admin credentials, unpatched plugin vulnerabilities, or misconfigured file permissions to plant malicious code. This means any site, from a small business blog to a large e-commerce platform, can unknowingly become a distribution node for malware, leading to reputational damage, blacklisting by search engines, and potential legal liability.

Defending against such threats demands a proactive security posture. Administrators must keep all CMS components, themes, and plugins fully patched, enforce strong password management, and implement file integrity monitoring. Web application firewalls and intrusion detection systems can block malicious payloads at the server edge, while regular malware scans help detect and remove injected code. Backup strategies ensure rapid recovery if a compromise occurs. For those managing their own hosting, selecting a provider that offers integrated security hardening reduces the operational burden.

In the broader hosting ecosystem, securing DNS resolution can add a valuable layer of defense. AEU DNS provides a private, secure DNS service that helps filter requests to known malicious domains, preventing users from ever reaching Redirection servers that might host GHOSTBLADE, thereby protecting both the website and its visitors without compromising speed or reliability.

Related AEU services

  • AEU Panel Managed hosting control panel
  • AEU-I IT and security consulting