logo

DarkSword Malware

ID: f770559e-b2d0-5eb4-bdc3-1b00ea38c66f

STIX ID: report--f770559e-b2d0-5eb4-bdc3-1b00ea38c66f

Feed Name: Schneier on Security

Threat Score
90/100

Date Published: 2026-05-05

Date Updated: 2026-05-13

Author: Bruce Schneier

...
...

GTIG identified "DarkSword," a full-chain iOS exploit leveraging six zero-day vulnerabilities (affecting iOS 18.4–18.7) used to install multiple malware families (GHOSTBLADE, GHOSTKNIFE, GHOSTSABER). The chain has been observed in campaigns by commercial surveillance vendors and suspected state-sponsored groups (including UNC6353) across Saudi Arabia, Turkey, Malaysia, and Ukraine; a leaked version has since enabled wider use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.