Unmasking DarkSword: GTIG Exposes Full-Chain iOS Exploit Used by Global Spies
ID: f5c982b5-8a77-5462-97c1-de12c803fc0d
STIX ID: report--f5c982b5-8a77-5462-97c1-de12c803fc0d
Feed Name: securityonline.info
GTIG disclosed the DarkSword iOS full-chain exploit kit used since at least November 2025 by commercial surveillance vendors and state-sponsored actors to achieve full device compromise across multiple countries; the chain leverages six vulnerabilities (several exploited as zero-days) to deliver kernel-capable spyware families (GHOSTBLADE/GHOSTKNIFE/GHOSTSABER). GTIG reported the flaws to Apple and patches were released in iOS 26.3; recommended mitigations include immediate updates to 26.3+, enabling Lockdown Mode for high-risk users, and cautious link/app hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
