DarkSword sites steal iPhone and iPad credentials

Published August 4, 2026

DarkSword is a leaked attack kit running on more than 100 websites. Affected iPhones and iPads can receive GHOSTBLADE, which steals credentials and files.

Report priority
High
Involves
iPhone

What is known

  • The attack begins when an iPhone or iPad opens a lure website.
  • Many sites display fake Apple or AWS sign-in pages.
  • A hidden page then targets six flaws in the affected iOS release.
  • If successful, it installs GHOSTBLADE and sends stolen credentials and files to the operator.
  • The implant then deletes crash records that could reveal its activity.

What to do

Compare the device's installed iOS version with the affected range. Versions 18.4 through 18.7 are exposed to the complete DarkSword chain. An affected version does not prove the device was compromised.

Install iOS 26, which closes the complete attack chain. Apple also issued an emergency patch for older devices. Lockdown Mode reportedly blocks these attacks, including on outdated software.

Reported details

Censys tracked a suspected Chinese-speaking operator using more than 100 web properties. Some displayed fake Apple or AWS sign-in pages, but no confirmed victim count was reported.

DarkSword combines six iOS vulnerabilities into one attack chain. Its leaked code has reportedly spread among at least seven, and probably eight, unrelated operators. Successful attacks install the GHOSTBLADE implant. It collects keychain, iCloud and Wi-Fi credentials, searches files, sends the data away and removes crash records.