Researchers from Google, iVerify, and Lookout disclosed DarkSword, a sophisticated iPhone exploit chain used in compromised websites to silently infect visitors, with observed targeting focused on Ukraine and additional activity tied to Saudi Arabia, Turkey, and Malaysia. The campaign is linked to suspected Russian operators, including activity tracked as UNC6353, and appears to support both espionage and financial theft, including the theft of saved passwords, text messages, and cryptocurrency wallet data. Reporting also indicates DarkSword is the second major iOS exploit kit recently found in the wild after Coruna, reinforcing concerns that advanced mobile exploitation is becoming more broadly operationalized rather than reserved for narrowly targeted, bespoke use.
Technical analysis shows DarkSword used multiple chained vulnerabilities to achieve full device compromise on older iOS versions, including JavaScriptCore bugs CVE-2025-31277 and CVE-2025-43529 for remote code execution, CVE-2026-20700 as a dyld PAC bypass, and sandbox escapes that pivoted from WebContent to the GPU process and then to mediaplaybackd. The exploit chain relied on first compromising WebKit and then abusing WebGPU/ANGLE-related paths to escape Safari’s sandbox, and Apple patched the flaws across later iOS releases including 18.6, 18.7.3, 26.2, and 26.3. Researchers warned that a substantial installed base of devices running iOS 18 or earlier remained exposed at the time of disclosure, making DarkSword notable both for its technical sophistication and for the scale of potentially vulnerable iPhones.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-01, Apple issued iOS 18.7.7 and iPadOS 18.7.7 to protect older devices that had not upgraded to iOS 26 from the DarkSword exploit chain. Apple said devices already running iOS 26 were protected and expanded the iOS 18 fix so more legacy devices could receive it automatically.
By 2026-03-24, researchers warned that a functional DarkSword exploit kit had been leaked on GitHub. The leak was described as an escalation that could let lower-skilled attackers launch DarkSword attacks at scale against still-vulnerable iPhones and iPads.
On 2026-03-23, CISA added three DarkSword-linked iOS vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to remediate them by 2026-04-03 under Binding Operational Directive 22-01. The directive followed public reporting that the flaws were actively exploited in DarkSword attacks.
On March 18, 2026, Google, Lookout, and iVerify publicly disclosed DarkSword, describing a full-chain Safari-based iOS exploit and associated malware families GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. Their reports detailed the six-vulnerability chain, links to Coruna-related infrastructure, and attribution to multiple threat actors including UNC6353.
After identifying the campaign infrastructure, Google added DarkSword delivery domains to Safe Browsing to help block access to malicious exploit sites. This was part of the defensive response alongside vulnerability disclosure to Apple.
On 2026-03-11, Apple released security updates for supported iOS 15 and 16 devices and warned users that outdated iPhones remained vulnerable to the Coruna and DarkSword exploit kits. Apple said fully updated supported devices are protected and that Lockdown Mode can block these attacks even on older systems.
Apple patched the vulnerabilities used by DarkSword across a series of iOS updates released from late 2025 through February 2026, with complete remediation available by iOS 26.3 and corresponding iOS 18 security updates. The fixes covered the six-flaw chain used for remote code execution, sandbox escape, PAC bypass, and kernel compromise.
Researchers observed DarkSword used by multiple actors against targets in Saudi Arabia, Turkey, and Malaysia in addition to Ukraine. Reported operators included UNC6748 and customers of Turkish surveillance vendor PARS Defense.
Beginning in December 2025, suspected Russian-linked actor UNC6353 used compromised Ukrainian websites to deliver DarkSword to visitors, selectively targeting Ukrainian users. The campaign focused on rapid data theft from iPhones rather than persistent surveillance.
Google Threat Intelligence Group said it reported the vulnerabilities used in DarkSword to Apple in late 2025. This disclosure started Apple's remediation process for the exploit chain.
Researchers said the DarkSword iOS exploit kit has been used since at least November 2025 against iPhones running affected iOS 18 versions. The framework was used by multiple actors and enabled rapid theft of sensitive data, including credentials and cryptocurrency wallet information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
cnet.com
Open sourcedarkreading.com
Open sourceboingboing.net
Open sourcescworld.com
Open sourceelmundo.es
Open sourcetherecord.media
Open sourceiverify.io
Open sourcelookout.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.