A New Crypto Predator Emerges: Google Exposes ‘Ghostblade’

bitcoinistPublicado em 2026-03-21Última atualização em 2026-03-21

Resumo

A new iOS malware called "Ghostblade," part of the DarkSword tool suite, has been exposed by Google Threat Intelligence. Designed to steal sensitive data from Apple devices, it targets cryptocurrency private keys, messages from iMessage, WhatsApp, and Telegram, as well as SIM details, location data, and media files. Ghostblade operates once, extracts information, and then deletes crash logs to avoid detection, leaving no persistent trace. This makes it particularly effective and hard to identify. The emergence of Ghostblade reflects a broader shift in cyberattacks toward individual crypto users rather than institutions. Although overall crypto hack losses dropped to around $50 million in February—down from $385 million the previous month—this decline is due to attackers shifting from code exploits to social engineering, phishing, and wallet poisoning schemes. The report underscores that high-value individual holders are increasingly targeted through deceptive websites and malware designed to operate quickly and discreetly.

Private crypto holders took the heaviest losses from hacking, phishing, and digital theft attempts in February 2026, according to blockchain intelligence firm Nominis — and a newly identified strain of iOS malware may explain part of why individual users have become the preferred target.

Designed To Strike Fast And Disappear

Google Threat Intelligence has identified a JavaScript-based malicious tool called Ghostblade, built specifically to hit Apple iOS devices, extract sensitive data, and go quiet before anyone notices.

The software is one of six tools bundled inside a broader package researchers are calling DarkSword. Together, the tools are engineered to steal cryptocurrency private keys, messaging data, and personal information from infected devices.

Ghostblade runs once, takes what it needs, and stops. No persistent background activity. No extra software required to make it work. That design makes it far harder to catch than malware that keeps running after an infection.

Source: Google

The tool also covers its tracks in a specific way. After it finishes, it wipes crash logs from the compromised device. Those logs are what Apple normally collects to identify software problems and flag suspicious activity. Without them, Apple receives no signal that anything went wrong.

What Ghostblade Can Actually Access

The scope of what Ghostblade can pull from a device is wide. Based on Google’s report, the malware is capable of reaching messages from iMessage, WhatsApp, and Telegram.

It can also collect SIM card details, location data, multimedia files, and system-level settings. For crypto users, the most direct threat is private key exposure — the kind of access that gives an attacker full control over a digital wallet with no way to reverse transactions once funds are moved.

Bitcoin is currently trading at $70,572. Chart: TradingView

The DarkSword suite represents a new chapter in browser-based attacks aimed at the crypto space, with Ghostblade serving as one of its most technically refined components.

Hackers Shift Focus From Code To People

Total losses from crypto-related hacks dropped sharply in February, falling to close to $50 million from $385 million the month before, Nominis data shows. But that decline does not signal a safer environment.

Reports indicate the drop reflects a change in method, not ambition. Attackers moved away from exploiting code vulnerabilities and toward phishing schemes, wallet poisoning, and other approaches that rely on tricking users rather than breaking systems.

Fake websites built to mirror legitimate platforms are a common vehicle. Users who land on them and interact with any element can have credentials and keys lifted without realizing it.

The Ghostblade alert from Google arrives against that backdrop — a reminder that high-value individual users, not just exchanges or protocols, are firmly in the crosshairs.

Featured image from Unsplash, chart from TradingView

Perguntas relacionadas

QWhat is the name of the newly identified iOS malware described in the article, and what is its primary function?

AThe malware is called Ghostblade. Its primary function is to extract sensitive data, such as cryptocurrency private keys, messaging data, and personal information, from infected Apple iOS devices and then go quiet to avoid detection.

QAccording to the article, what broader package is Ghostblade a part of, and what is the collective goal of its tools?

AGhostblade is one of six tools bundled inside a broader package called DarkSword. The collective goal of these tools is to steal cryptocurrency private keys, messaging data, and personal information from infected devices.

QHow does the Ghostblade malware avoid detection after it completes its task on a compromised device?

AGhostblade avoids detection by running only once, taking the data it needs, and then stopping with no persistent background activity. It also covers its tracks by wiping crash logs from the device, which prevents Apple from receiving signals that would normally flag suspicious activity.

QWhat specific types of data can the Ghostblade malware access on an infected device?

AGhostblade can access messages from iMessage, WhatsApp, and Telegram. It can also collect SIM card details, location data, multimedia files, system-level settings, and most critically for crypto users, private keys that control digital wallets.

QWhat trend in cyber attacks does the article highlight, as shown by the change in total crypto losses from January to February 2026?

AThe article highlights a trend where attackers are shifting their focus from exploiting code vulnerabilities to using methods that trick users, such as phishing schemes and wallet poisoning. This is evidenced by a sharp drop in total losses from $385 million in January to about $50 million in February, which reflects this change in method rather than a decrease in attacker ambition.

Leituras Relacionadas

Luno Cuts 20% of Global Workforce as Cryptocurrency Exchange Shifts Priorities Towards Automation

Luno, a global cryptocurrency exchange owned by Digital Currency Group, is reducing its global workforce by 20% as part of a major operational restructuring driven by a downturn in retail crypto activity and increased automation. CEO James Lanigan announced the layoffs on July 28, stating it was a difficult but necessary decision to build a more sustainable structure for the long term. The company did not disclose the total number of affected employees, though South African staff are among those impacted, with formal consultations initiated there in line with local labor laws. This marks the second major round of layoffs in three and a half years, following a 35% staff reduction in January 2023. The company cites cyclical declines in retail user activity and ongoing investment in automated tools as key factors behind the restructuring, which has fundamentally changed the firm's resource needs. Concurrently, Luno is reorganizing into three unified divisions built on a single core platform: 1) a consolidated consumer and API platform serving over 16 million users in Africa and Asia-Pacific, 2) a stablecoin solutions unit focused on the zar-backed 'Zaru' stablecoin launched in February 2026, and 3) an institutional arm offering OTC services and cross-border settlement networks. This restructuring follows recent market withdrawals, with Luno discontinuing services in certain markets from September 1, 2026.

cryptonews.ruHá 38m

Luno Cuts 20% of Global Workforce as Cryptocurrency Exchange Shifts Priorities Towards Automation

cryptonews.ruHá 38m

Turkey blocked 47,493 illegal betting sites amid expanded measures targeting cryptocurrency accounts

Turkey has blocked access to 47,493 illegal betting websites since January 1st as part of a nationwide crackdown on online gambling operators and their payment networks. Police and gendarmerie conducted 680 operations, detaining 5,629 suspects, with 3,231 placed in pre-trial detention and 1,515 placed under judicial supervision. Cybercrime units are conducting 24/7 monitoring of illegal betting sites, social media ads, and digital payment channels. Investigators are tracking bank accounts, e-money services, and crypto asset wallets suspected of facilitating betting operations or laundering criminal proceeds. The actions follow earlier raids in May targeting over 670 suspects, with one investigation in Adana uncovering cryptocurrency platforms used for laundering betting revenues. Authorities highlighted a specific case involving a network allegedly coordinated by a suspect with initials İ.Ö.Ö., which reportedly generated revenue from illegal betting and match-fixing. Prosecutors identified seven overseas crypto wallets that received transfers from this network, estimating total transaction volume at $4 billion. All related bank and crypto accounts were frozen. The network allegedly recruited individuals to act as "common accounts" for processing bets in exchange for a 1% commission. In separate operations, authorities blocked 4,742 bank accounts and six crypto accounts in Adana, and identified transactional activity worth approximately $104 million across 47 suspects. Assets including companies, vehicles, and properties were seized. The crackdown includes real-time disruption. During the 2022 World Cup final, prosecutors identified and ordered the freezing of 6,314 bank accounts used for illegal betting, aided by an AI analysis system called AVCI. They project illegal betting volume for the 2026 World Cup could reach $50 billion. Justice Minister Yılmaz Tunç stated that 19 offshore "financial companies" managing panel systems for illegal betting sites were identified, with legal proceedings initiated against 23 suspects. He emphasized a strategic shift towards "draining the swamp" through coordinated asset seizures and digital evidence collection, rather than relying on individual prosecutions.

cryptonews.ruHá 44m

Turkey blocked 47,493 illegal betting sites amid expanded measures targeting cryptocurrency accounts

cryptonews.ruHá 44m

Trading

Spot
活动图片