TF-MAL-js.ghostblade
📛 Threat Title
Malware family: GHOSTBLADE
Description
ThreatFox malware family `js.ghostblade`. Printable name: GHOSTBLADE.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.ghostblade
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.ghostblade
IOC database
- Type
- domain
- Value
js.ghostblade- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.ghostblade
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.ghostblade
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cloud.google.com
GTIG has identified three distinct malware families deployed following a successful DarkSword compromise: GHOSTBLADE , GHOSTKNIFE, and GHOSTSABER. The proliferation of this single exploit chain across disparate threat actors mirrors the previously discovered Coruna iOS exploit kit.
-
web:coincentral.com
DarkSword hits iOS 18.4-18.7, stealing crypto wallets and personal data. Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more. Exploit triggers via fake sites; no user action needed to infect devices. Final-stage malware self-deletes after stealing sensitive data quickly ...
-
web:cybersecsentinel.com
The exploit chain targets iOS versions 18.4 through 18.7 and delivers three distinct malware families: GHOSTBLADE , GHOSTKNIFE, and GHOSTSABER. These are capable of exfiltrating virtually every category of data from a compromised device, including credentials, cryptocurrency wallet and exchange data, iCloud files, location history, SMS messages ...
-
web:securityboulevard.com
In Ukraine, attackers compromised at least two Ukrainian websites, including a government site. Upon successful exploitation, malware is executed on the device. The type of malware depends on the attacker. In the Ukrainian campaign, that malware is known as Ghostblade , one example of a payload delivered via the DarkSword exploit chain.
-
web:thecyberexpress.com
Researchers disclose a new iOS full-chain exploit kit dubbed DarkSword — a name taken directly from a variable buried inside the malware's own code.
-
web:thecybersecguru.com
The Payloads: Ghostblade , Ghostknife, and Ghostsaber What the Malware Steals The Financial Motive: Targeting Crypto Wallets Who is Behind DarkSword? The Threat Actors UNC6353: Russian State-Sponsored Espionage UNC6748: Commercial Surveillance (PARS Defense) The Scale of the Threat: Are You Vulnerable? Apple's Response and Mitigation Strategies
-
web:thehackernews.com
DarkSword exploit targets iOS 18.4-18.7 using 6 flaws and 3 zero-days, enabling rapid data theft from iPhones across multiple countries.
-
web:www.f5.com
Successful compromises deploy malware families such as GHOSTKNIFE (a JavaScript backdoor for data exfiltration and device control), GHOSTSABER (a JavaScript backdoor for enumeration, file listing, and arbitrary code execution), and GHOSTBLADE (a JavaScript dataminer collecting extensive device and personal data).
-
web:www.macworld.com
According to the report, a toolkit called DarkSword has been used to create three malware families called Ghostblade , Ghostknife, and Ghostsaber, and iPhones running iOS 18.4 to 18.7 are vulnerable.
-
web:www.malwarebytes.com
In Ukraine, attackers compromised at least two Ukrainian websites, including a government site. Upon successful exploitation, malware is executed on the device. The type of malware depends on the attacker. In the Ukrainian campaign, that malware is known as Ghostblade , one example of a payload delivered via the DarkSword exploit chain.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.