logo

Unmasking DarkSword: GTIG Exposes Full-Chain iOS Exploit Used by Global Spies

ID: f5c982b5-8a77-5462-97c1-de12c803fc0d

STIX ID: report--f5c982b5-8a77-5462-97c1-de12c803fc0d

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-03-22

Date Updated: 2026-04-23

Author: Ddos

...
...

GTIG disclosed the DarkSword iOS full-chain exploit kit used since at least November 2025 by commercial surveillance vendors and state-sponsored actors to achieve full device compromise across multiple countries; the chain leverages six vulnerabilities (several exploited as zero-days) to deliver kernel-capable spyware families (GHOSTBLADE/GHOSTKNIFE/GHOSTSABER). GTIG reported the flaws to Apple and patches were released in iOS 26.3; recommended mitigations include immediate updates to 26.3+, enabling Lockdown Mode for high-risk users, and cautious link/app hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.