Google Flags Ghostblade as New Crypto-Stealing Malware Targeting iOS Devices

Google Flags Ghostblade as New Crypto-Stealing Malware Targeting iOS Devices

First seen 21 Mar 2026, 21:55 UTC Mexc.CoMexc 91% similarity 61.5

Article Content

Browse articles
ThreatCluster

Google Threat Intelligence has identified a new crypto-stealing malware named 'Ghostblade' that specifically targets Apple iOS devices. This malware is part of the DarkSword suite, designed to rapidly extract sensitive information, including private keys and messaging data from apps like iMessage, Telegram, and WhatsApp. Ghostblade operates using JavaScript and does not maintain a continuous presence on the device, making it harder to detect. It activates, collects data, and then ceases operations, while also deleting crash reports to evade detection by Apple. The malware can also harvest SIM card information, multimedia files, geolocation data, and access system settings. This development highlights the evolving tactics used by cybercriminals to exploit vulnerabilities in crypto-related applications. The broader implications of Ghostblade reflect ongoing trends in crypto-related cyber threats, particularly those targeting iOS users. As of now, there are no specific patches or mitigation strategies disclosed for this malware.

Key Points: • Ghostblade is a new JavaScript-based malware targeting iOS devices to steal crypto-related data. • The malware operates transiently, activating only to extract data before shutting down, complicating detection. • It can access sensitive information from messaging apps and delete crash reports to avoid detection.

ThreatCluster AI How this analysis works

Timeline

2026-03-21
Google Threat Intelligence publishes findings on Ghostblade malware.

Community

Browse all →

Tracked Entities in This Story