A New Crypto Predator Emerges: Google Exposes ‘Ghostblade’

bitcoinistXuất bản vào 2026-03-21Cập nhật gần nhất vào 2026-03-21

Tóm tắt

A new iOS malware called "Ghostblade," part of the DarkSword tool suite, has been exposed by Google Threat Intelligence. Designed to steal sensitive data from Apple devices, it targets cryptocurrency private keys, messages from iMessage, WhatsApp, and Telegram, as well as SIM details, location data, and media files. Ghostblade operates once, extracts information, and then deletes crash logs to avoid detection, leaving no persistent trace. This makes it particularly effective and hard to identify. The emergence of Ghostblade reflects a broader shift in cyberattacks toward individual crypto users rather than institutions. Although overall crypto hack losses dropped to around $50 million in February—down from $385 million the previous month—this decline is due to attackers shifting from code exploits to social engineering, phishing, and wallet poisoning schemes. The report underscores that high-value individual holders are increasingly targeted through deceptive websites and malware designed to operate quickly and discreetly.

Private crypto holders took the heaviest losses from hacking, phishing, and digital theft attempts in February 2026, according to blockchain intelligence firm Nominis — and a newly identified strain of iOS malware may explain part of why individual users have become the preferred target.

Designed To Strike Fast And Disappear

Google Threat Intelligence has identified a JavaScript-based malicious tool called Ghostblade, built specifically to hit Apple iOS devices, extract sensitive data, and go quiet before anyone notices.

The software is one of six tools bundled inside a broader package researchers are calling DarkSword. Together, the tools are engineered to steal cryptocurrency private keys, messaging data, and personal information from infected devices.

Ghostblade runs once, takes what it needs, and stops. No persistent background activity. No extra software required to make it work. That design makes it far harder to catch than malware that keeps running after an infection.

Source: Google

The tool also covers its tracks in a specific way. After it finishes, it wipes crash logs from the compromised device. Those logs are what Apple normally collects to identify software problems and flag suspicious activity. Without them, Apple receives no signal that anything went wrong.

What Ghostblade Can Actually Access

The scope of what Ghostblade can pull from a device is wide. Based on Google’s report, the malware is capable of reaching messages from iMessage, WhatsApp, and Telegram.

It can also collect SIM card details, location data, multimedia files, and system-level settings. For crypto users, the most direct threat is private key exposure — the kind of access that gives an attacker full control over a digital wallet with no way to reverse transactions once funds are moved.

Bitcoin is currently trading at $70,572. Chart: TradingView

The DarkSword suite represents a new chapter in browser-based attacks aimed at the crypto space, with Ghostblade serving as one of its most technically refined components.

Hackers Shift Focus From Code To People

Total losses from crypto-related hacks dropped sharply in February, falling to close to $50 million from $385 million the month before, Nominis data shows. But that decline does not signal a safer environment.

Reports indicate the drop reflects a change in method, not ambition. Attackers moved away from exploiting code vulnerabilities and toward phishing schemes, wallet poisoning, and other approaches that rely on tricking users rather than breaking systems.

Fake websites built to mirror legitimate platforms are a common vehicle. Users who land on them and interact with any element can have credentials and keys lifted without realizing it.

The Ghostblade alert from Google arrives against that backdrop — a reminder that high-value individual users, not just exchanges or protocols, are firmly in the crosshairs.

Featured image from Unsplash, chart from TradingView

Câu hỏi Liên quan

QWhat is the name of the newly identified iOS malware described in the article, and what is its primary function?

AThe malware is called Ghostblade. Its primary function is to extract sensitive data, such as cryptocurrency private keys, messaging data, and personal information, from infected Apple iOS devices and then go quiet to avoid detection.

QAccording to the article, what broader package is Ghostblade a part of, and what is the collective goal of its tools?

AGhostblade is one of six tools bundled inside a broader package called DarkSword. The collective goal of these tools is to steal cryptocurrency private keys, messaging data, and personal information from infected devices.

QHow does the Ghostblade malware avoid detection after it completes its task on a compromised device?

AGhostblade avoids detection by running only once, taking the data it needs, and then stopping with no persistent background activity. It also covers its tracks by wiping crash logs from the device, which prevents Apple from receiving signals that would normally flag suspicious activity.

QWhat specific types of data can the Ghostblade malware access on an infected device?

AGhostblade can access messages from iMessage, WhatsApp, and Telegram. It can also collect SIM card details, location data, multimedia files, system-level settings, and most critically for crypto users, private keys that control digital wallets.

QWhat trend in cyber attacks does the article highlight, as shown by the change in total crypto losses from January to February 2026?

AThe article highlights a trend where attackers are shifting their focus from exploiting code vulnerabilities to using methods that trick users, such as phishing schemes and wallet poisoning. This is evidenced by a sharp drop in total losses from $385 million in January to about $50 million in February, which reflects this change in method rather than a decrease in attacker ambition.

Nội dung Liên quan

SUI đang đứng trước ngưỡng cửa đột phá mới khi 'phe bò' nhắm mục tiêu tăng lên 20 USD

Ngày 1/8, mạng Sui đã mở khóa khoảng 13,72 triệu token SUI, trị giá khoảng 9,9 triệu USD, tương đương 0,34% nguồn cung lưu thông. Số token này được phân bổ cho quỹ dự trữ cộng đồng, người tham gia sớm và kho bạc của Mysten Labs. Khác với hình thức mở khóa ồ ạt, Sui áp dụng cơ chế giải phóng từ từ hàng ngày nhằm giảm áp lực bán. Nhà giao dịch nổi tiếng CryptoPatel nhận định vùng giá hiện tại của SUI (khoảng 0,68 USD) là khu vực tích lũy với mục tiêu dài hạn lần lượt là 5, 10 và 20 USD. Tuy nhiên, giá token đã giảm hơn 5% trong những phiên gần đây, và tâm lý thị trường ngắn hạn đang trở nên thận trọng. Về mặt cơ bản, mạng Sui ghi nhận một số phát triển tích cực: Quỹ đầu tư Mubadala Capital của Abu Dhabi đã phát hành phiên bản token hóa quỹ thị trường tư nhân trị giá 75 triệu USD trên nền tảng Sui, hướng đến các nhà đầu tư tổ chức. Ngoài ra, mạng thử nghiệm Hashi cho phép sử dụng Bitcoin làm tài sản thế chấp đã ra mắt, cùng với việc triển khai chuyển khoản ổn định miễn phí trong mạng. Việc giảm giá gần đây được cho là chủ yếu do áp lực từ đợt mở khóa token và điều kiện thị trường chung, không phải từ sự cố nào của chính giao thức Sui.

cryptonews.ru3 phút trước

SUI đang đứng trước ngưỡng cửa đột phá mới khi 'phe bò' nhắm mục tiêu tăng lên 20 USD

cryptonews.ru3 phút trước

Cách Mua Tiền Điện Tử An Toàn Tại Minnesota (Không Có Máy ATM)

Từ ngày 1/8/2026, Minnesota (Mỹ) thực hiện thay đổi lớn về mua và lưu trữ tiền điện tử. Các máy ATM tiền điện tử (cryptocurrency kiosks) tại trạm xăng, cửa hàng tiện lợi bị cấm hoàn toàn do bị lợi dụng cho các vụ lừa đảo. Trong cùng ngày, một luật mới có hiệu lực, cho phép ngân hàng và liên đoàn tín dụng tại Minnesota cung cấp dịch vụ lưu ký tiền điện tử cho khách hàng. Lý do cấm máy ATM tiền điện tử: Chúng là công cụ ưa thích của kẻ lừa đảo, thường nhắm vào người già. Từ 2023-2025, Minnesota điều tra 134 khiếu nại với tổn thất gần 1 triệu USD. Luật mới nhằm loại bỏ công cụ rủi ro này và mở ra con đường an toàn, được quản lý hơn. Cách lưu trữ mới qua ngân hàng: Khi tiền điện tử được lưu ký tại ngân hàng, nó được bảo vệ bởi các quy tắc: tách biệt tài sản khách hàng với tài sản ngân hàng, chịu sự giám sát thực sự, và ngân hàng phải nộp thông báo trước 60 ngày cùng kế hoạch quản lý rủi dục chi tiết cho cơ quan quản lý. Mô hình này tương tự bảo quản tài sản vật lý trong tủ an toàn. Tình hình hiện tại: St. Cloud Financial Credit Union là tổ chức tiên phong, ra mắt dịch vụ lưu ký từ tháng 3/2026. Các ngân hàng khác dự kiến sẽ theo sau khi hoàn tất các yêu cầu pháp lý. Các cách mua an toàn khác: Cư dân Minnesota vẫn có thể mua tiền điện tử qua các sàn giao dịch trực tuyến được cấp phép. Cần cảnh giác cao với bất kỳ cuộc gọi/email áp lực, đe dọa yêu cầu chuyển tiền mặt thành tiền điện tử ngay lập tức – đó là dấu hiệu lừa đảo rõ ràng. FAQ tóm tắt: 1. Kiểm tra giấy phép của sàn giao dịch trực tuyến trên website Bộ Thương mại Minnesota. 2. Áp lực mua ngay lập tức là dấu hiệu lừa đảo. 3. Báo cáo lừa đảo cho FBI (IC3.gov) và Văn phòng Tổng chưởng lý Minnesota. 4. Mua tiền điện tử không chịu thuế, nhưng bán/đổi/dùng để mua hàng thì có (thuế lợi tức vốn). 5. Ví tự lưu trữ (self-custody wallet) an toàn hơn trước nguy cơ sàn phá sản. Dịch vụ lưu ký ngân hàng tại Minnesota được thiết kế để bảo vệ tài sản khách hàng trong trường hợp này.

cryptonews.ru11 phút trước

Cách Mua Tiền Điện Tử An Toàn Tại Minnesota (Không Có Máy ATM)

cryptonews.ru11 phút trước

Giao dịch

Giao ngay
活动图片