GHOSTBLADE

Malware type
spyware
Last IoC activity
2026-06-22 17:29:23
Profile updated
2026-07-07 13:17:59

Context

According to Google, GHOSTBLADE is delivered via the DarkSword exploit chain. GHOSTBLADE is a dataminer written in JavaScript that collects and exfiltrates a wide variety of data from a compromised device. Data collected by GHOSTBLADE is exfiltrated to an attacker-controlled server over HTTP(S). Unlike GHOSTKNIFE and GHOSTSABER, GHOSTBLADE is less capable and does not support any additional modules or backdoor-like functionality; it also does not operate continuously. However, similar to GHOSTKNIFE, GHOSTBLADE also contains code to delete crash reports, but targets a different directory where they may be stored.

Reports & references

  • cloud.google.com — Darksword Ios Exploit Chain (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Ghostblade (report)

External references