On March 20th, Google Threat Intelligence Group reported that an iOS exploit chain named DarkSword is targeting iPhones running iOS versions 18.4 to 18.7. Attackers are using compromised websites to deploy a malware known as Ghostblade, which specifically searches for and steals data from cryptocurrency Centralized Exchanges (CEXs) including Coinbase, Binance, Kraken, Kucoin, OKX, and MEXC, as well as wallet applications such as Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe. Furthermore, Ghostblade also synchronizes and steals sensitive information like SMS messages, iMessages, contacts, Wi-Fi passwords, geolocation, and chat logs from Telegram and WhatsApp. The malware is designed for rapid data exfiltration, automatically deleting temporary files and terminating its operation after data collection is complete. Related attack activities have currently been observed in regions including Saudi Arabia, Turkey, Malaysia, and Ukraine.
All Comments