Last seven days
- First activity
- Sep 7, 2026
- Last activity
- Sep 7, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
DarkSword is a publicly leaked, full-chain iOS exploit kit and spyware framework targeting unpatched iPhone and iPad devices, principally iOS and iPadOS 18.4 through 18.7.
Profile source: Mallory opens in a new tabDarksword
DarkSword is a publicly leaked, full-chain iOS exploit kit and spyware framework targeting unpatched iPhone and iPad devices, principally iOS and iPadOS 18.4 through 18.7. It chains six vulnerabilities—including WebKit/JavaScriptCore, sandbox-escape, pointer-authentication bypass, and kernel flaws—to obtain remote code execution, escape application sandboxes, and gain elevated kernel-level access. It is delivered through compromised websites, watering holes, impersonated sign-in pages, and other lure pages that silently stage version-specific browser exploits in hidden content.
Following successful exploitation, DarkSword deploys post-exploitation components, including GHOSTBLADE modules, to collect Keychain material, saved Wi-Fi credentials, iCloud data, files, messages, contacts, photographs, browser data, call and location history, and application data. Some observed deployments target cryptocurrency-wallet credentials, seed phrases, and mnemonics. DarkSword can monitor keyboard input when targeted wallet applications are active, encrypt and exfiltrate collected data to operator-controlled infrastructure, inject into iOS system processes, and remove diagnostic artifacts or delete itself to hinder forensic detection.
DarkSword activity has been observed since at least November 2025 in campaigns targeting victims in Saudi Arabia, Turkey, Malaysia, and Ukraine. It was initially associated with commercial surveillance vendors and suspected state-sponsored operators; public leakage subsequently enabled adoption by multiple additional operators, including criminal users. The exploit chain relies on vulnerabilities for which Apple has issued security fixes, making updated Apple devices protected against the documented exploit stages.
Reported operators
The renderer CVEs and the staging pattern overlap with the publicly documented “DarkSword” iOS exploit kit.
DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.
In mid-March, when three cybersecurity firms — iVerify, Lookout, and Google’s Threat Intelligence Group — published coordinated findings about an exploit kit they named DarkSword. Researchers found it sitting openly on compromised Ukrainian websites... Any visitor on an unpatched iPhone running iOS 18.4 through 18.6.2 would have been silently compromised the moment the page loaded.
Apple has patched the vulnerabilities associated with the DarkSword exploit chain for all affected customers... DarkSword leaked to GitHub on March 22... We’ve observed a handful of campaigns being conducted with the malware, to include [an] email phishing campaign conducted by TA446 which spoofed the Atlantic Council.
A major new cybersecurity threat has emerged for iPhone users worldwide, as researchers have uncovered a new hacking tool called DarkSword. According to a joint investigation by Google, Lookout, and iVerify, hundreds of millions of people could be at risk if they have not updated their software recently.
Exploited software
MITRE ATT&CK
Reporting
Thirteen trojanized Composer theme packages for the OphimCMS and KKPhim streaming-site ecosystems injected malicious JavaScript into every visitor page, sending users to gambling and ad-fraud content and selectively attacking externally referred, non-desktop visitors. On vulnerable iPhones, the packages delivered a FUNNULL-hosted WebKit-to-kernel exploit chain targeting CVE-2025-31277, CVE-2025-43529, and an AppleM2ScalerCSCDriver kernel primitive; the campaign targeted iOS 18.4 through 18.6.x rather than updated versions. The spyware harvested keychain data, messages, photos, browser cookies, location history, and cryptocurrency wallet seed phrases, then exfiltrated them to rotating command-and-control infrastructure. Operators redeployed the exploit chain and added wallet theft capabilities, while FUNNULL-linked infrastructure has continued operating after sanctions, with activity reportedly being separated from the FUNNULL CDN brand.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.