Skip to main content
← Back to Demos
Malware advanced · 15 min

Multi-engine scan flags GHOSTBLADE-style iOS implant

The August 3 digest reported a Chinese threat actor deploying GHOSTBLADE-style implants on iOS using a leaked DarkSword toolset, marking a new mobile spyware campaign. The same week, the AsyncAPI npm supply chain was hit after attackers exploited a weak GitHub Actions workflow, stealing the publish token and shipping five malicious versions across four packages. Mobile spyware implants typically arrive as malicious .ipa bundles; once a user installs and opens the app, the implant gains access to messages, credentials, and device data. Metascan scans the IPA with 30+ anti-malware engines to detect known implant families. The demo file is the EICAR test file embedded in an IPA — a safe, standard detection test — so no real malware is executed.

Attack Technique

Mobile spyware implant

MITRE ATT&CK

T1204.002 ↗

Platforms

linuxwindows

File Types

.txt

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---