DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover
ID: f83feea4-9eae-557b-8f12-5c862cb380f0
STIX ID: report--f83feea4-9eae-557b-8f12-5c862cb380f0
Feed Name: The Hacker News
A newly discovered iOS exploit kit named DarkSword leverages multiple zero-day and known vulnerabilities to chain remote code execution, GPU and daemon sandbox escapes, and kernel privilege escalation to deploy an infostealer (GHOSTBLADE) and JavaScript backdoors that rapidly exfiltrate extensive personal and crypto-related data; the kit has been used in watering-hole campaigns since November 2025 by multiple actors (including suspected Russian-linked UNC6353, UNC6748, and the commercial vendor PARS Defense) targeting iOS 18.4–18.7 and highlights active exploit proliferation and a market for high-end iOS offensive capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
