logo

Three lessons from DarkSword: inside a government-grade iPhone exploit kit

ID: a68ca95b-1b70-58cb-9b20-ab358efd8f2f

STIX ID: report--a68ca95b-1b70-58cb-9b20-ab358efd8f2f

Feed Name: Jamf Blog

Threat Score
85/100

Date Published: 2026-04-20

Date Updated: 2026-07-16

...
...

Jamf Threat Labs analyzes the leaked DarkSword iOS exploit kit source code, which implements one‑click remote code execution and full sandbox escape across many device/firmware combinations (iOS 18.4–18.6.2). The leak contains unobfuscated development builds with verbose debug output, crypto-wallet targeting (indicative of financial motives), Russian-language artifacts and deployment traces, and demonstrates that government-grade exploit capabilities can proliferate beyond sophisticated operators, increasing risk to unpatched iPhone users.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.