DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike
ID: 621963f7-2b71-50cb-b808-ed1fdfbb2483
STIX ID: report--621963f7-2b71-50cb-b808-ed1fdfbb2483
Feed Name: Dark Reading
DarkSword is a multi-zero-day iOS exploit chain (affecting iOS 18.4–18.7) that enables one-click full device compromise and rapid data exfiltration; it uses multiple CVEs across JavaScriptCore, ANGLE, dyld, and the iOS kernel to achieve RCE, sandbox escape, and privilege escalation, and delivers malware families Ghostblade, Ghostknife, and Ghostsaber. Observed since November 2025, DarkSword has been used by suspected espionage group UNC6353 and by commercial surveillance vendors (including activity linked to PARS Defense) to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine; operators have also targeted cryptocurrency wallets, indicating dual espionage and financial motives. Users are advised to update to iOS 18.7.6 or iOS 26.3.1 and consider Lockdown Mode.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
