Multiple Threat Actors Exploiting a Six-Vulnerability iOS Exploit Kit Dubbed “DarkSword”
ID: 43a4fc6e-cdb1-5434-a7f0-fe3b648c3992
STIX ID: report--43a4fc6e-cdb1-5434-a7f0-fe3b648c3992
Feed Name: The Cyber Express
DarkSword is a JavaScript-only iOS full-chain exploit kit that used six chained vulnerabilities (including two JavaScriptCore RCEs and a dyld PAC bypass) to escape WebKit, inject into privileged processes, obtain kernel read-write, and rapidly exfiltrate SMS/iMessage, call history, contacts, passwords, Telegram/WhatsApp history, iCloud files and cryptocurrency wallet keys. Delivered via geofenced watering-hole sites (compromised Ukrainian domains) and observed across Ukraine, Saudi Arabia, Turkey and Malaysia, the kit was used by multiple actors — including suspected state-linked UNC6353 and commercial surveillance vendors — and was patched across iOS 26.1–26.3 with final remediation in iOS 18.7.3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
