INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

DarkSword Exploit Tool Used in Global Attacks

| 2026-03-23 08:37 CRITICAL MEDIUM
Executive Summary AI-generated
The DarkSword exploit kit, a sophisticated cyber-espionage framework, has been linked to multiple threat groups and Russian intelligence agencies. Its delivery mechanism exploits six vulnerabilities tracked as CVE-2025-31277 through CVE-2025-43520 in iOS devices. These flaws enable attackers to escape sandboxes, escalate privileges, and gain remote code execution on unpatched iPhones. The kit was used in watering-hole attacks targeting Ukrainian websites of e-commerce, industrial equipment, and local services organizations. CISA has ordered federal agencies to secure their devices within two weeks by April 3, as mandated by Binding Operational Directive (BOD) 22-01.
Technical Mitigations AI-generated
* Implement secure coding practices: Ensure that developers and maintainers of iOS applications use secure coding practices, such as input validation and sanitization, to prevent exploitation of vulnerabilities like those found in DarkSword. * Use up-to-date security patches: Regularly update iPhone software with the latest security patches to ensure that known vulnerabilities are addressed before they can be exploited by attackers. * Implement sandboxing and isolation: Use robust sandboxes and isolation mechanisms to limit the attack surface of iOS devices, making it more difficult for attackers to escape or escalate privileges. * Monitor for suspicious activity: Continuously monitor iPhone usage patterns and detect any unusual behavior that may indicate a threat is present on an infected device.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-20700CVE-2026-20700 CVE-2025-43529CVE-2025-43529 CVE-2020-27950CVE-2020-27950 CVE-2022-48503CVE-2022-48503 CVE-2025-43510CVE-2025-43510 CVE-2024-23225CVE-2024-23225 CVE-2023-32434CVE-2023-32434 CVE-2023-41974CVE-2023-41974 CVE-2025-31277CVE-2025-31277 CVE-2023-32409CVE-2023-32409 CVE-2020-27932CVE-2020-27932 CVE-2021-30952CVE-2021-30952 CVE-2024-23222CVE-2024-23222 CVE-2024-23296CVE-2024-23296 CVE-2025-14174CVE-2025-14174 CVE-2025-43520CVE-2025-43520 CVE-2023-38606CVE-2023-38606 CVE-2023-43000CVE-2023-43000
Target & Sectors
SA MY UA RU CN
governmentgovernment defensedefense
Incident Timeline
February 2025
Threat actors used a previously unseen JavaScript framework delivered by an iOS exploit chain from a surveillance vendor's customer to target the Ios.
infrastructure Ios
tactic T1059.007 - JavaScript
late 2025
Threat actors used a new iOS exploit kit called DarkSword to target surveillance vendors and likely nation-state actors.
infrastructure Ios
organisation Lookout Threat Labs
organisation iVerify
organisation Google
November 2025
Threat actors used DarkSword to exploit vulnerabilities in iOS devices.
March 11, 2026
Threat actors used a vulnerability in DarkSword iOS to exploit attacks on affected devices.
infrastructure Ios
organisation Safari’s Safe Browsing
infrastructure 15 devices Devices
2026-03-16
Threat actors used a combination of CVE-2025-31277, CVE-2026-20700, and CVE-2025-43529 vulnerabilities exploited attacks on the DarkSword iOS delivery framework.
vulnerability CVE-2025-31277
vulnerability CVE-2026-20700
attribution CVE-2025-43529
vulnerability CVE-2025-14174
attribution CVE-2025-43510
vulnerability CVE-2025-43520
attribution Google Threat Intelligence Group
attribution iVerify
attribution CVE-2025
2026-03-23
The threat actors behind the exploit kit, UNC6353, used advanced iOS exploit chains in watering hole attacks on Ukrainian websites.
infrastructure Ios
organisation Apple
organisation UNC6353
organisation UNC6691
organisation iPhones
organisation DarkSword
organisation CVE-2025-43529
organisation CVE-2025-43510
organisation CVE-2025-43520
organisation PAC
infrastructure 8.6 JavaScriptCore memory corruption
infrastructure 18.4
infrastructure 18.6.2
infrastructure 13.0
infrastructure 17.2.1
organisation Google
infrastructure 17.2
infrastructure 13.0 iPhones
infrastructure 18.7
infrastructure 18.4 iPhones
organisation UNC6748
organisation SecurityAffairs
organisation WebContent
organisation CVE-2022
organisation CVE-2023-41974
organisation CVE-2023-38606
organisation PPL Bypass Carbone No
organisation PPL Bypass Rocket CVE-2024-23296
organisation GhostBlade
organisation GhostKnife
organisation PlasmaLoader
organisation The Red Report 2026
April 3
CISA added three of the six DarkSword vulnerabilities to its catalog, ordering Federal Civilian Executive Branch agencies to patch their devices by April 3.
vulnerability CVE-2025-31277
attribution CVE-2025-43510
attribution CVE-2025-43520
attribution Federal Civilian Executive Branch
attribution FCEB
general_metric 6 DarkSword vulnerabilities
Tactical Metrics
Metrics
infrastructure
​Ios
Affected Product
Metrics
infrastructure
9
Javascriptcore Memory Corruption
Metrics
infrastructure
​18.4
Software Version
Metrics
infrastructure
​18.6.2
Software Version
Metrics
infrastructure
15
Devices Devices
Metrics
infrastructure
​13.0
Software Version
Metrics
infrastructure
​17.2.1
Software Version
Metrics
infrastructure
​17.2
Software Version
Metrics
infrastructure
13
Iphones
Metrics
infrastructure
​18.7
Software Version
Metrics
infrastructure
18
Iphones
Intelligence Sources