DarkSword is a fully weaponized iOS exploit kit and spyware delivery framework targeting Apple devices running iOS and iPadOS 18.4 through 18.7. It is built around a six-vulnerability full-chain exploit that enables compromise through web content, including watering-hole and lure-site scenarios, with little or no user interaction beyond visiting a malicious or compromised page. After successful exploitation, DarkSword has been observed deploying post-exploitation payloads including GHOSTBLADE and, in some reporting, related payload families such as GHOSTKNIFE and GHOSTSABER.
Operationally, DarkSword is associated with fake sign-in pages, Apple-themed lures, and compromised legitimate websites used to stage the exploit chain. The attack flow commonly involves a hidden frame or staging component that selects exploit logic based on the victim device’s iOS version, then executes the chain to obtain elevated code execution and access sensitive device data. Observed post-compromise behavior includes theft of keychain material, iCloud-related data, saved Wi-Fi credentials, files, and other personal information; some reporting also attributes harvesting of contacts, messages, call history, browser data, photos, notes, emails, authentication-related data, and cryptocurrency wallet information. Exfiltration to operator-controlled infrastructure is a core function.
DarkSword-linked operations have also used credential-harvesting decoys, including Apple ID-themed pages, alongside the exploit infrastructure, indicating combined session and credential theft objectives in some campaigns. Anti-forensics behavior has been reported, including deletion of crash artifacts and self-cleanup to reduce forensic visibility.
The toolkit is believed to have originated in the commercial surveillance ecosystem and has been linked to use by commercial surveillance vendors, suspected state-sponsored actors, and later criminal or opportunistic operators after a public leak in 2026 accelerated proliferation. Victim targeting has been reported in Saudi Arabia, Turkey, Malaysia, and Ukraine, with additional reporting tying use to watering-hole campaigns against Ukrainian websites and phishing-led activity by other actors. Infrastructure analysis indicates rapid server rotation, multiple operator panels, and use by several distinct operators, including at least one Chinese-speaking cluster and overlap in some environments with the related Coruna exploit ecosystem.
DarkSword is notable as an example of government-grade or commercial-spyware capability escaping controlled use and becoming more broadly accessible. Apple has issued patches and backported protections for affected devices, and fully updated systems are reported to be protected against the known DarkSword chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, two vulnerabilities and a multi-component exploit kit were directly connected to active malware campaigns, including a sophisticated iOS full-chain exploit called DarkSword that delivered the GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads.
The addition of the three Apple vulnerabilities to the KEV catalog comes in the wake of reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout about an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.
The addition of the three Apple vulnerabilities to the KEV catalog comes in the wake of reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout about an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.
The addition of the three Apple vulnerabilities to the KEV catalog comes in the wake of reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout about an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
what makes DarkSword remarkable isn’t just that it works. It’s how it systematically defeats every layer of defense Apple built. | CVE-2026–20700, a vulnerability in dyld (the dynamic linker), let DarkSword bypass that too.
what makes DarkSword remarkable isn’t just that it works. It’s how it systematically defeats every layer of defense Apple built.
what makes DarkSword remarkable isn’t just that it works. It’s how it systematically defeats every layer of defense Apple built.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.
In mid-March, when three cybersecurity firms — iVerify, Lookout, and Google’s Threat Intelligence Group — published coordinated findings about an exploit kit they named DarkSword. Researchers found it sitting openly on compromised Ukrainian websites... Any visitor on an unpatched iPhone running iOS 18.4 through 18.6.2 would have been silently compromised the moment the page loaded.
Apple has patched the vulnerabilities associated with the DarkSword exploit chain for all affected customers... DarkSword leaked to GitHub on March 22... We’ve observed a handful of campaigns being conducted with the malware, to include [an] email phishing campaign conducted by TA446 which spoofed the Atlantic Council.
A major new cybersecurity threat has emerged for iPhone users worldwide, as researchers have uncovered a new hacking tool called DarkSword. According to a joint investigation by Google, Lookout, and iVerify, hundreds of millions of people could be at risk if they have not updated their software recently.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign targets iPhones running iOS 18.4 through 18.7 and is designed to steal highly sensitive data after a victim visits a lure site.
Load exploit chain : The iframe pulls the six-vulnerability DarkSword chain (kernel driver exploit, MIG filter bypass, PAC bypass, sandbox escape), targeting iOS 18.4 through 18.7.
T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion) ; Leurre : page AWS, iOS ou Apple ID impersonée
The operators also try to remove signs of compromise by deleting crash reports and RemoteLog.log before exiting.
The operators also try to remove signs of compromise by deleting crash reports and RemoteLog.log before exiting.
The infrastructure included fake AWS console pages, Apple ID credential-harvesting pages, and other disposable lure fronts.
A DarkSword az érintett készülékeken személyes adatok (névjegyek, üzenetek, híváselőzmények, hitelesítéshez szükséges információk) megszerzésére képes
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A leaked six-vulnerability iOS exploit chain and exploit kit that uses malicious lure pages and hidden staging content to compromise iPhones, bypass protections, gain deeper device access, and deploy follow-on modules for data theft.
An iOS exploit kit / exploit chain used via malicious lure sites and compromised web properties to gain deeper access to targeted iPhones, bypass protections, and facilitate theft of sensitive device data.
A full-chain iOS exploit kit targeting iOS 18.4 through 18.7. It is used via watering-hole and fake login-page lures to trigger patched iOS vulnerabilities, execute JavaScript, and facilitate deployment of follow-on malware such as GHOSTBLADE.
Commercial iOS exploit chain used by multiple operators to compromise iOS 18.4–18.7 devices. It delivers post-exploitation capability via staging pages and operator panels, enabling deployment of follow-on modules and C2-managed operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.