State snoops and spyware vendors planting info-stealing malware on iPhones, Google warns
ID: 63aaaf65-3dc9-56d1-b561-ca80f7c470a0
STIX ID: report--63aaaf65-3dc9-56d1-b561-ca80f7c470a0
Feed Name: The Register (Security)
Researchers from Google, iVerify, and Lookout analyzed an active iOS exploit kit named DarkSword (affecting iOS 18.4–18.7) that chains six patched CVEs to perform RCE, bypass PAC/TPRO mitigations, escape sandboxes via GPU flaws, exploit a kernel driver, and escalate privileges to deploy JavaScript backdoors (GhostKnife, GhostSaber, GhostBlade) that steal messages, recordings, location, accounts and cryptocurrency data; multiple threat clusters and commercial surveillance vendors have used DarkSword in distinct watering‑hole campaigns against targets in Saudi Arabia, Turkey, Malaysia and Ukraine.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
