Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Chinese Hackers Use Fake Apple ID and AWS Pages to Target iPhones with GHOSTBLADE Malware

Chinese Hackers Use Fake Apple ID and AWS Pages to Target iPhones with GHOSTBLADE Malware

By: Jordan Vector Cybersecurity Expert

Last updated: August 4, 2026

Human Written
Chinese Hackers Use Fake Apple ID and AWS Pages to Target iPhones with GHOSTBLADE Malware
  • A Chinese-speaking cybercriminal is targeting iPhone users through fake websites mimicking AWS and Apple ID login pages using the DarkSword hacking tool.

  • The malware dubbed GHOSTBLADE is known for stealing login information such as keychain, iCloud, and Wi-Fi credentials through the use of an iframe in iOS versions 18.4 to 18.7.

  • Operator panels reveal “Asia-Pacific Group” name and Telegram contact, providing the first direct lead for tracking the campaign’s command infrastructure.

Researchers discovered an extensive espionage campaign in which a Chinese threat actor uses a leaked variant of the DarkSword iOS Exploit Kit.

The actor runs over 100 fake web properties, which they use to lure victims into malicious sites delivering the payload.

Security researchers from Censys, an attack surface management firm, uncovered the operation and reported their findings on July 31, 2026.

This campaign relies on decoy login forms that resemble login pages for Amazon Web Services and Apple IDs, in order to deploy the GHOSTBLADE info stealer.

Details of the Attack Chain from a Fake Login to Full Compromise

The attack begins when a victim visits one of the operator’s fake domains. The page appears as a legitimate AWS console or Apple ID sign-in screen. Behind the scenes, a hidden iframe loads JavaScript that triggers the DarkSword exploit chain.

DarkSword exploits six vulnerabilities in the range of iOS 18.4 to 18.7 versions. These vulnerabilities are related to the iOS kernel, WebKit and sandbox security features.

According to the researchers, DarkSword allows running code on the kernel level without the need of any user actions other than visiting the malicious website. The sophistication of such exploits is mirrored in claims of zero-click iPhone exploits that bypass security without any user interaction. The attacker obtains keychain data, iCloud credentials and Wi-Fi passwords.

As a result of exploitation, the implant loads and executes the GHOSTBLADE modules that dump keychain data, iCloud credentials and saved Wi-Fi passwords. Afterwards, the malware searches for all necessary files and packages and transmits the data to the attacker’s server.

Aidan Holland of Censys pointed out that “the hosting is mostly concentrated in Hong Kong, but also reaches Japan, the US, and Europe”. The infrastructure rotates rapidly, with individual hosts surviving only days before being replaced.

Distinctive Operator Panels Provide Hunting Clues

The Censys investigation identified three separate login panels used by the operator cluster. The “DarkSword Admin” panel appeared on seven hosts across three countries as of July 30, 2026. One panel at IP address 38.22.89[.]117:8888 displayed Chinese-language labels for “username,” “password,” and “Log in”.

One very striking thing about this is the C2 Control Panel. It uses a dark background color that’s almost black with red color accents. The panel also had animation particle effects, and the display of the group name “亚太集团” (Asia-Pacific Group).

Also, there was the presence of a Telegram contact link on the page t[.]me/YATA0000. Holland described this as the first-ever direct contact channel they’ve recovered for this particular operator.

The cluster runs the leaked kit rather than a reimplementation. Evidence includes a shared staging-page hash and Russian-language code comments carried over from the leaked source.

Wider Implications and Infrastructure Overlap

Google’s Threat Intelligence Group, along with iVerify and Lookout, discovered the DarkSword kit earlier this year. Starting from November 2025, attackers deployed this tool in attacks against Saudi Arabia, Malaysia, Turkey, as well as Ukraine. The source code leak on GitHub expanded access to additional threat actors.

The Censys investigation uncovered overlaps with another exploit kit called Coruna. A Singapore-based host (38.181.52[.]95) hosted administration panels for both Coruna and DarkSword simultaneously.

Coruna targets older iOS versions from 3.0 through 17.2.1. Evidence suggests a threat actor who goes by the name UNC6353 used both kits in attacks against Ukrainian targets.

Researchers also found an open directory listing in Frankfurt (93.152.221[.]37) exposing the operator’s tooling. The directory contained an SSH key comment reading “jkcing@apt,” a web-content fuzzer, and references to a previously undocumented malware family called Thorn C2.

The operation’s scale and infrastructure churn indicate a well-resourced actor. The Censys label currently covers 27 hosts and 180 web properties, though the numbers fluctuate as the operator spins up and abandons domains.

Share this article

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.