DarkSword is a sophisticated web-delivered iOS and iPadOS exploit kit used to fully compromise Apple mobile devices and deploy post-exploitation spyware payloads. It has been observed in active campaigns since at least late 2025 and targets devices running iOS and iPadOS 18.4 through 18.7. The exploit chain has been described as using multiple vulnerabilities, including zero-days, across components such as JavaScriptCore, dyld, and the iOS sandbox to achieve kernel-level code execution with little or no user interaction beyond visiting a malicious or compromised website.
DarkSword has been associated with watering-hole operations on legitimate but compromised sites and has also been linked to phishing-driven campaigns by additional actors after the toolkit leaked publicly in 2026. Reporting ties its use to multiple commercial surveillance vendors, suspected state-sponsored operators, and later criminal or opportunistic adopters. Observed victim geography includes Saudi Arabia, Turkey, Malaysia, and Ukraine, and separate reporting links adoption to Russian espionage-linked activity including TA446/COLDRIVER.
Following successful exploitation, DarkSword has been used to deliver several payload families, including GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. Reported post-compromise behavior includes theft of messages, passwords, browser history, photos, notes, emails, location data, cryptocurrency wallet data, and other sensitive device content. Some reporting also describes traffic interception support through proxy-configuration bypass components and anti-forensic behavior intended to remove traces of compromise after collection. The toolkit’s modular architecture has been described as including redirector, loader, remote-code-execution, and bypass components, enabling operators to adapt stages independently.
DarkSword is notable for the apparent proliferation of a government-grade mobile exploitation capability beyond its original operators. Its public leak materially increased the risk of reuse by a broader set of threat actors and prompted unusual backported Apple security updates for older supported iOS branches. The activity around DarkSword is widely regarded as evidence that advanced iPhone exploitation and commercial spyware capabilities are becoming more accessible and more broadly operationalized.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Additionally, two vulnerabilities and a multi-component exploit kit were directly connected to active malware campaigns, including a sophisticated iOS full-chain exploit called DarkSword that delivered the GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads.
The addition of the three Apple vulnerabilities to the KEV catalog comes in the wake of reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout about an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.
The addition of the three Apple vulnerabilities to the KEV catalog comes in the wake of reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout about an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.
The addition of the three Apple vulnerabilities to the KEV catalog comes in the wake of reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout about an iOS exploit kit codenamed DarkSword that leverages these shortcomings, along with three bugs, to deploy various malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER for data theft.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
what makes DarkSword remarkable isn’t just that it works. It’s how it systematically defeats every layer of defense Apple built. | CVE-2026–20700, a vulnerability in dyld (the dynamic linker), let DarkSword bypass that too.
what makes DarkSword remarkable isn’t just that it works. It’s how it systematically defeats every layer of defense Apple built.
what makes DarkSword remarkable isn’t just that it works. It’s how it systematically defeats every layer of defense Apple built.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In mid-March, when three cybersecurity firms — iVerify, Lookout, and Google’s Threat Intelligence Group — published coordinated findings about an exploit kit they named DarkSword. Researchers found it sitting openly on compromised Ukrainian websites... Any visitor on an unpatched iPhone running iOS 18.4 through 18.6.2 would have been silently compromised the moment the page loaded.
DarkSword is a sophisticated piece of malware—probably government designed—that targets iOS. Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices.
Apple has patched the vulnerabilities associated with the DarkSword exploit chain for all affected customers... DarkSword leaked to GitHub on March 22... We’ve observed a handful of campaigns being conducted with the malware, to include [an] email phishing campaign conducted by TA446 which spoofed the Atlantic Council.
A major new cybersecurity threat has emerged for iPhone users worldwide, as researchers have uncovered a new hacking tool called DarkSword. According to a joint investigation by Google, Lookout, and iVerify, hundreds of millions of people could be at risk if they have not updated their software recently.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack framework used a “watering hole” technique, stealthily targeting visitors who loaded infected pages. Researchers said vulnerable iPhones could be compromised simply by visiting a hacked website.
Commercial spyware, often developed by private firms, exploits software vulnerabilities to gain access.
We’ve observed a handful of campaigns being conducted with the malware, to include [an] email phishing campaign conducted by TA446 which spoofed the Atlantic Council.
They infect devices when the user simply visits a compromised legitimate site, use a chain of vulnerabilities to escape the browser sandbox, and silently exfiltrate messages, calls, location, browser history, Wi-Fi passwords, health data, notes and crypto wallets.
18 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as part of the same extensively reported mobile exploit-chain story involving sophisticated exploitation of iOS and other mobile operating systems.
An iPhone exploit kit used in watering-hole attacks via compromised websites. It could silently compromise vulnerable iPhones upon page load and access messages, passwords, browser history, photos, notes, emails, and cryptocurrency wallet data.
Recently leaked exploit kit referenced as part of public exploit chains against modern iOS.
An iOS full-chain exploit used to fully compromise iPhones/iOS devices via multiple zero-day vulnerabilities and deploy final-stage surveillance payloads. It has been used by commercial surveillance vendors and suspected state-sponsored actors in distinct campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.