Articles
Crypto Market Analysis

Google Threat Intel flags 'Ghostblade' crypto-stealing malware

User Image

Por Anônimo

Criado March 21, 2026|2 mins de leitura
Main Image

Ghostblade is one of six malware tools in the "DarkSword" suite of malicious software designed to steal crypto private keys and user data.

Google Threat Intelligence has identified a new form of crypto-stealing malware called “Ghostblade” that affects Apple iOS devices and is part of the “DarkSword” suite of browser-based malware tools designed to steal private keys and other sensitive information.

Ghostblade is written in JavaScript and designed for rapid data theft. The crypto-stealing malware activates, grabs sensitive data from the compromised device, and relays it to malicious servers, according to Google Threat Intelligence.

The Ghostblade malware does not run 24/7 on the compromised device, does not require extra plug-ins to function, and stops functioning after extracting data, making it more difficult to detect, the threat researchers said.

The malware also includes code that deletes crash reports from the compromised device, preventing Apple from receiving them and flagging the malicious software.

Ghostblade can access and relay messaging data from the iMessage texting application for Apple devices, Telegram and WhatsApp.

The malicious software can also steal SIM card information, identity, multimedia and geolocation data, and access system settings, according to the Google cybersecurity report.

DarkSword and its components are one of the latest cybersecurity threats identified by Google Threat researchers, shedding light on the evolving methods used by malicious actors to steal crypto and other valuable data from unsuspecting users.

Related: Google uncovers iOS exploit kit used in crypto phishing attacks

Losses from crypto hacks fell to $49 million in February, a sharp decrease from $385 million in January, according to blockchain intelligence platform Nominis.

This drop reflects a pivot from code-based cyber threats to crypto phishing attempts, wallet poisoning attacks and other threat vectors that take advantage of human error, Nominis said in its report.

Phishing attempts typically use fake websites designed to look legitimate. These fake websites often use URLs that are nearly identical to the legitimate sites they masquerade as, tricking users into visiting them.

These sites embed malware that can steal crypto private keys and other valuable data when a user accesses the site or clicks any of its elements. 

Magazine: WazirX hackers prepped 8 days before attack, swindlers fake fiat for USDT: Asia Express

Source: CoinTelegraph


Outros artigos publicados recentemente

Live updates: Bitcoin slips back to $77,000 after challenging $80,000 overnight
Live updates: Bitcoin slips back to $77,000 after challenging $80,000 overnight

Bitcoin

Spot bitcoin ETFs pulled in $606 million on Aug. 20 and ether funds $221 million, both bigger than t...

How a Treasury buyback tweak helped bitcoin surge 25% to nearly $80,000 in days
How a Treasury buyback tweak helped bitcoin surge 25% to nearly $80,000 in days

Bitcoin

Treasury buybacks are not QE, analysts said, but the move helped pull long-term yields off 19-year h...

Zcash jumps 48% to over $800 as Grayscale spot ETF push adds to ‘next bitcoin’ buzz
Zcash jumps 48% to over $800 as Grayscale spot ETF push adds to ‘next bitcoin’ buzz

Bitcoin

ZEC traded above its January 2018 peak as futures volume hit billions of dollars and a Grayscale fil...

Strategy sits on $1.4 billion profit on bitcoin holdings as price surges
Strategy sits on $1.4 billion profit on bitcoin holdings as price surges

Bitcoin

Strategy’s common stock rose 10% in Friday pre-market trading to $120, the highest level in two mo...

Treasury's latest measure isn't QE or YCC. Still, bitcoin is skyrocketing. Here's why.
Treasury's latest measure isn't QE or YCC. Still, bitcoin is skyrocketing. Here's why.

Bitcoin

The rally in hard assets isn’t necessarily about what the Treasury is doing, but what its move sig...

Coldcard ships firmware after $114 million bitcoin theft; says AI helped catch more bugs
Coldcard ships firmware after $114 million bitcoin theft; says AI helped catch more bugs

Bitcoin

Three weeks of review turned up problems unrelated to the flaw that cost users $114 million, but upd...