DarkSword is a publicly leaked, full-chain iOS exploit kit and spyware delivery framework targeting iPhones and iPads running vulnerable iOS or iPadOS 18.4 through 18.7 releases. It chains six vulnerabilities to obtain browser-based code execution, escape application sandboxing, bypass pointer-authentication protections, and gain kernel-level privileges before deploying post-exploitation payloads including GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. GHOSTBLADE components collect Keychain material, saved Wi-Fi credentials, iCloud data, messages, contacts, call history, browser data, photos, notes, location information, files, and account data; observed variants also target cryptocurrency-wallet seed phrases and mnemonics. Collected information is encrypted and exfiltrated to attacker-controlled infrastructure. DarkSword operators use compromised websites, watering-hole pages, Apple-themed lures, and fraudulent sign-in pages to initiate version-specific exploitation, often through concealed browser content. The framework includes anti-forensic cleanup intended to remove local artifacts after operation. DarkSword activity has been observed since at least November 2025 against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine, initially associated with commercial surveillance vendors and suspected state-sponsored actors. Following public leakage, the toolkit has been adopted by multiple additional operators, including criminal users. UNC6353, a suspected Russian espionage actor, has been linked to watering-hole use of DarkSword. Apple patches and Lockdown Mode reduce exposure to the known browser-based attack chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
La chaîne WebKit-to-kernel présente un « overlap avec le kit d’exploit iOS DarkSword »; le texte indique qu’il s’agit d’une variante distincte.
La chaîne WebKit-to-kernel présente un « overlap avec le kit d’exploit iOS DarkSword »; le texte indique qu’il s’agit d’une variante distincte.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Additionally, two vulnerabilities and a multi-component exploit kit were directly connected to active malware campaigns, including a sophisticated iOS full-chain exploit called DarkSword that delivered the GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The renderer CVEs and the staging pattern overlap with the publicly documented “DarkSword” iOS exploit kit.
DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.
In mid-March, when three cybersecurity firms — iVerify, Lookout, and Google’s Threat Intelligence Group — published coordinated findings about an exploit kit they named DarkSword. Researchers found it sitting openly on compromised Ukrainian websites... Any visitor on an unpatched iPhone running iOS 18.4 through 18.6.2 would have been silently compromised the moment the page loaded.
Apple has patched the vulnerabilities associated with the DarkSword exploit chain for all affected customers... DarkSword leaked to GitHub on March 22... We’ve observed a handful of campaigns being conducted with the malware, to include [an] email phishing campaign conducted by TA446 which spoofed the Atlantic Council.
A major new cybersecurity threat has emerged for iPhone users worldwide, as researchers have uncovered a new hacking tool called DarkSword. According to a joint investigation by Google, Lookout, and iVerify, hundreds of millions of people could be at risk if they have not updated their software recently.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign targets iPhones running iOS 18.4 through 18.7 and is designed to steal highly sensitive data after a victim visits a lure site.
Load exploit chain : The iframe pulls the six-vulnerability DarkSword chain (kernel driver exploit, MIG filter bypass, PAC bypass, sandbox escape), targeting iOS 18.4 through 18.7.
Once compromised, according to Frielingsdorf, Coruna injected its code into legitimate system processes such as the power daemon and location daemon rather than running a dedicated spyware process, making detection more difficult.
T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion) ; Leurre : page AWS, iOS ou Apple ID impersonée
Once compromised, according to Frielingsdorf, Coruna injected its code into legitimate system processes such as the power daemon and location daemon rather than running a dedicated spyware process, making detection more difficult.
The operators also try to remove signs of compromise by deleting crash reports and RemoteLog.log before exiting.
The operators also try to remove signs of compromise by deleting crash reports and RemoteLog.log before exiting.
Once triggered, DarkSword can bypass protections, access device data...
iVerify researchers saw new variants with improved jailbreak and virtualization detection functionality...
The infrastructure included fake AWS console pages, Apple ID credential-harvesting pages, and other disposable lure fronts.
T1056.003 — Input Capture: Web Portal Capture (Collection) ; 103.106.190[.]217 : co-héberge le panel “C2 Control Panel” et une page de phishing Apple ID
He also says DarkSword is designed to steal "basically everything," including keychain credentials, Wi‑Fi passwords, iCloud data, photos and notes, and more.
A victim who reaches a malicious page is served a staging page that silently loads a hidden frame and selects exploit code based on the iOS version.
A DarkSword az érintett készülékeken személyes adatok (névjegyek, üzenetek, híváselőzmények, hitelesítéshez szükséges információk) megszerzésére képes
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
59 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named exploit kit mentioned only as an analogy for the WebKit-to-kernel iOS exploit chain; the content does not state that DarkSword was deployed in this campaign.
iOS exploit kit with overlapping JavaScriptCore/WebKit exploitation techniques. The reported chain uses browser exploitation, an IOSurface/mach cross-process pivot, PAC-pointer forgery, and a kernel escape.
A publicly documented iOS exploit kit referenced for its overlapping WebKit renderer-exploitation and staging techniques. The report does not establish that DarkSword itself delivered the campaign payload.
A sophisticated iOS exploit chain/spyware framework used against iPhones to achieve RCE, sandbox escape, and privilege escalation, then deliver payloads and steal extensive device data including credentials, iCloud content, photos, notes, and cryptocurrency wallet data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.