A leaked iPhone exploit kit called DarkSword is being used by a Chinese threat actor to infect devices across 100 websites. Victims visit a fake AWS or Apple login page. No tap required. The implant dumps iCloud credentials, Wi-Fi passwords, and files.
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS
An unknown Chinese threat actor runs leaked DarkSword across 100-plus web properties, using fake AWS and Apple logins to deploy GHOSTBLADE on iOS.
thehackernews.com