logo

DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike

ID: 621963f7-2b71-50cb-b808-ed1fdfbb2483

STIX ID: report--621963f7-2b71-50cb-b808-ed1fdfbb2483

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

DarkSword is a multi-zero-day iOS exploit chain (affecting iOS 18.4–18.7) that enables one-click full device compromise and rapid data exfiltration; it uses multiple CVEs across JavaScriptCore, ANGLE, dyld, and the iOS kernel to achieve RCE, sandbox escape, and privilege escalation, and delivers malware families Ghostblade, Ghostknife, and Ghostsaber. Observed since November 2025, DarkSword has been used by suspected espionage group UNC6353 and by commercial surveillance vendors (including activity linked to PARS Defense) to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine; operators have also targeted cryptocurrency wallets, indicating dual espionage and financial motives. Users are advised to update to iOS 18.7.6 or iOS 26.3.1 and consider Lockdown Mode.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.