GhostBlade is a JavaScript-based iOS information-stealing malware family deployed after successful exploitation by the DarkSword full-chain iOS exploit kit. It has been observed in targeted operations since at least late 2025 against iPhones running vulnerable iOS 18.4 through 18.7 builds, including campaigns attributed to multiple actors such as commercial surveillance customers, suspected state-sponsored operators, and the Russia-linked actor COLDRIVER/TA446. Reported targeting has included government, think tank, higher education, financial, legal, and regional targets in countries including Saudi Arabia, Turkey, Malaysia, and Ukraine.
GhostBlade functions as an aggressive post-exploitation dataminer and access-validation implant. After DarkSword achieves browser-based code execution, sandbox escape, and elevated privileges, GhostBlade modules are delivered to profile the device, validate access, and harvest sensitive data. Observed collection objectives include keychain contents, iCloud data, saved Wi-Fi credentials, files, and in broader DarkSword-linked reporting, victim data such as messages, location history, and cryptocurrency-wallet-related information. The malware exfiltrates collected data to operator-controlled infrastructure and is associated with short-lived, rapidly rotated web infrastructure used for staging, collection, and operator panels.
GhostBlade has been described as part of a trio of DarkSword-delivered malware families alongside GhostKnife and GhostSaber. Compared with those families, GhostBlade is most consistently characterized as the infostealing component. Delivery has been observed through watering-hole and lure-based web exploitation, including spoofed sign-in pages and targeted email campaigns that redirected selected iPhone users into the DarkSword chain. The malware and surrounding exploit workflow have also been associated with anti-forensic cleanup behavior intended to reduce post-compromise artifacts after data theft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
7 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, two vulnerabilities and a multi-component exploit kit were directly connected to active malware campaigns, including a sophisticated iOS full-chain exploit called DarkSword that delivered the GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads... 28 CVE-2026-32183 99 Apple iOS / iPadOS (DarkSword Chain) CWE-119 – Memory Corruption No | Additionally, two vulnerabilities and a multi-component exploit kit were directly connected to active malware campaigns, including a sophisticated iOS full-chain exploit called DarkSword that delivered the GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads.
CVE-2025-43520 (CVSS score: 8.8) - A memory corruption vulnerability in Apple's kernel component that could allow a malicious application to cause unexpected system termination or write kernel memory. (Fixed in December 2025) | ...an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.
...an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft. | CVE-2025-43510 (CVSS score: 7.8) - A memory corruption vulnerability in Apple's kernel component that could allow a malicious application to cause unexpected changes in memory shared between processes. (Fixed in December 2025)
CVE-2025-31277 (CVSS score: 8.8) - A vulnerability in Apple WebKit that could result in memory corruption when processing maliciously crafted web content. (Fixed in July 2025) | ...an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Deploy GHOSTBLADE modules: On successful exploitation, the implant drops keychain, iCloud, and Wi-Fi credential-dumping modules and begins the file-exfiltration sweep.
Depending on the threat actor, a successful compromise deployed distinct malware families we track as GHOSTBLADE, GHOSTKNIFE, or GHOSTSABER.
Depending on the threat actor, a successful compromise deployed distinct malware families we track as GHOSTBLADE, GHOSTKNIFE, or GHOSTSABER.
Proofpoint and Malfors also revealed that another Russia-linked threat actor known as COLDRIVER (aka TA446) has exploited the DarkSword kit to deliver the GHOSTBLADE data stealer malware in attacks targeting government, think tank, higher education, financial, and legal entities.
Artifacts left behind from the Webpack process applied to the analyzed GHOSTBLADE sample included file paths that show the structure on disk of these libraries (Figure 22). We assess that GHOSTBLADE was likely developed by the DarkSword developers, based on the consistency in coding styles and the tight integration between it and the library code, which is notably distinct from how GHOSTKNIFE and GHOSTSABER leveraged these libraries.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign targets iPhones running iOS 18.4 through 18.7 and is designed to steal highly sensitive data after a victim visits a lure site.
50 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A payload module delivered by DarkSword that collects credentials, keychain contents, iCloud data, saved Wi‑Fi passwords, and files from compromised iPhones before exfiltration.
A payload module set delivered by DarkSword to collect credentials, keychain contents, iCloud data, Wi-Fi passwords, and files from compromised iPhones.
An information-stealing iOS implant deployed after successful DarkSword exploitation. It delivers modules for dumping keychain, iCloud, and Wi-Fi credentials and performs file exfiltration to attacker-controlled endpoints.
Post-exploitation module set deployed through the DarkSword chain. It steals keychain contents, iCloud data, and Wi‑Fi credentials, exfiltrates data to C2 endpoints, and includes cleanup behavior to remove traces.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.