Skip to content

Darksword

DarkSword is a publicly leaked, full-chain iOS exploit kit and spyware framework targeting unpatched iPhone and iPad devices, principally iOS and iPadOS 18.4 through 18.7.

Profile source: Mallory opens in a new tab

Darksword

Family profile

DarkSword is a publicly leaked, full-chain iOS exploit kit and spyware framework targeting unpatched iPhone and iPad devices, principally iOS and iPadOS 18.4 through 18.7. It chains six vulnerabilities—including WebKit/JavaScriptCore, sandbox-escape, pointer-authentication bypass, and kernel flaws—to obtain remote code execution, escape application sandboxes, and gain elevated kernel-level access. It is delivered through compromised websites, watering holes, impersonated sign-in pages, and other lure pages that silently stage version-specific browser exploits in hidden content.

Following successful exploitation, DarkSword deploys post-exploitation components, including GHOSTBLADE modules, to collect Keychain material, saved Wi-Fi credentials, iCloud data, files, messages, contacts, photographs, browser data, call and location history, and application data. Some observed deployments target cryptocurrency-wallet credentials, seed phrases, and mnemonics. DarkSword can monitor keyboard input when targeted wallet applications are active, encrypt and exfiltrate collected data to operator-controlled infrastructure, inject into iOS system processes, and remove diagnostic artifacts or delete itself to hinder forensic detection.

DarkSword activity has been observed since at least November 2025 in campaigns targeting victims in Saudi Arabia, Turkey, Malaysia, and Ukraine. It was initially associated with commercial surveillance vendors and suspected state-sponsored operators; public leakage subsequently enabled adoption by multiple additional operators, including criminal users. The exploit chain relies on vulnerabilities for which Apple has issued security fixes, making updated Apple devices protected against the documented exploit stages.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Keylogging
  • Post Exploitation
  • Privilege Escalation
  • Process Injection
  • Spoofing

Observed infrastructure

Last seven days

First activity
Sep 7, 2026
Last activity
Sep 7, 2026
Feed role
Distribution
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

Reported operators

Threat actors

5 named in public reporting
GTIG-URL

The renderer CVEs and the staging pattern overlap with the publicly documented “DarkSword” iOS exploit kit.

UNC6353

DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.

Google Threat Intelligence Group

In mid-March, when three cybersecurity firms — iVerify, Lookout, and Google’s Threat Intelligence Group — published coordinated findings about an exploit kit they named DarkSword. Researchers found it sitting openly on compromised Ukrainian websites... Any visitor on an unpatched iPhone running iOS 18.4 through 18.6.2 would have been silently compromised the moment the page loaded.

Star Blizzard

Apple has patched the vulnerabilities associated with the DarkSword exploit chain for all affected customers... DarkSword leaked to GitHub on March 22... We’ve observed a handful of campaigns being conducted with the malware, to include [an] email phishing campaign conducted by TA446 which spoofed the Atlantic Council.

UNC6748

A major new cybersecurity threat has emerged for iPhone users worldwide, as researchers have uncovered a new hacking tool called DarkSword. According to a joint investigation by Google, Lookout, and iVerify, hundreds of millions of people could be at risk if they have not updated their software recently.

Exploited software

Vulnerabilities linked to Darksword

20 CVEs

MITRE ATT&CK

Darksword in ATT&CK

45 distinct techniques

Reporting

Research mentioning Darksword

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.