New “Darksword” iOS exploit used in infostealer attack on iPhones
ID: d0794b66-74c0-526f-be17-9db999b7aaf8
STIX ID: report--d0794b66-74c0-526f-be17-9db999b7aaf8
Feed Name: Bleeping Computer
A sophisticated iOS exploit kit dubbed "DarkSword" (targeting iOS 18.4–18.7) has been used since at least November 2025 to deliver data‑stealing malware (GHOSTBLADE, GHOSTKNIFE, GHOSTSABER) via compromised websites and watering‑hole attacks, exfiltrating credentials, messages, location, and cryptocurrency wallet data; multiple actors including UNC6748, UNC6353 and PARS Defense customers have been observed using the chain, which leverages several CVEs that Apple has since patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
