logo

DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover

ID: f83feea4-9eae-557b-8f12-5c862cb380f0

STIX ID: report--f83feea4-9eae-557b-8f12-5c862cb380f0

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A newly discovered iOS exploit kit named DarkSword leverages multiple zero-day and known vulnerabilities to chain remote code execution, GPU and daemon sandbox escapes, and kernel privilege escalation to deploy an infostealer (GHOSTBLADE) and JavaScript backdoors that rapidly exfiltrate extensive personal and crypto-related data; the kit has been used in watering-hole campaigns since November 2025 by multiple actors (including suspected Russian-linked UNC6353, UNC6748, and the commercial vendor PARS Defense) targeting iOS 18.4–18.7 and highlights active exploit proliferation and a market for high-end iOS offensive capabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.