logo

State snoops and spyware vendors planting info-stealing malware on iPhones, Google warns

ID: 63aaaf65-3dc9-56d1-b561-ca80f7c470a0

STIX ID: report--63aaaf65-3dc9-56d1-b561-ca80f7c470a0

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-03-18

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Researchers from Google, iVerify, and Lookout analyzed an active iOS exploit kit named DarkSword (affecting iOS 18.4–18.7) that chains six patched CVEs to perform RCE, bypass PAC/TPRO mitigations, escape sandboxes via GPU flaws, exploit a kernel driver, and escalate privileges to deploy JavaScript backdoors (GhostKnife, GhostSaber, GhostBlade) that steal messages, recordings, location, accounts and cryptocurrency data; multiple threat clusters and commercial surveillance vendors have used DarkSword in distinct watering‑hole campaigns against targets in Saudi Arabia, Turkey, Malaysia and Ukraine.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.