INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

DarkSword Exploit Kit Targets iOS Devices

| 2026-03-19 09:14 CRITICAL MEDIUM
Executive Summary AI-generated
The DarkSword exploit kit, codenamed "DarkSword," has been used in distinct campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine. The kit is designed to target iPhones running iOS versions between 18.4 and 18.7 and is deployed by a suspected Russian espionage group named UNC6353. This threat actor operates with motives aligned with Russian intelligence requirements. Lookout has assessed that the group may be a Russia-backed privateer or criminal proxy threat actor, lacking strong engineering resources or proper OPSEC measures. The kit's capabilities include cryptocurrency theft and intelligence gathering, making it a sophisticated threat. DarkSword is also linked to other exploit kits, including Coruna and GHOSTSABER, which have been used in previous campaigns.
Technical Mitigations AI-generated
* Implement a secure boot mechanism to ensure that the iOS device boots with a trusted and validated kernel, preventing exploitation of vulnerabilities before they can be patched. * Regularly update and patch all software components, including operating systems, apps, and plugins, to prevent exploitation of known vulnerabilities. * Use a secure web browsing experience by disabling JavaScript and other potentially vulnerable features in Safari or Chrome, and instead use a secure browser like Tor Browser for sensitive activities. * Implement a robust anti-malware solution that includes real-time detection and removal of threats, including those related to the DarkSword exploit kit.
AI Podcast (EN) detail_available
detail_listen_ai (EN)
Intelligence distributed on:
Incident Link
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Campaign Expands AcrossCampaign Expands Across CVE-2025-14174CVE-2025-14174 CVE-2025-31277CVE-2025-31277 CVE-2025-43510CVE-2025-43510 CVE-2025-43520CVE-2025-43520 CVE-2026-20700CVE-2026-20700 CVE-2025-43529CVE-2025-43529
Target & Sectors
NORTH_AMERICA NORTH_AMERICA APAC APAC
Incident Timeline
‎November 2025
DarkSword iOS Exploit Kit uses six flaws, including CVE-2026-20700 and CVE-2025-43529.
tactic Exfiltration
tactic T1059.007 - JavaScript
organisation GHOSTSABER
organisation UNC6748
source_region Saudi Arabia
organisation GHOSTKNIFE
organisation Multiple Sophisticated
infrastructure Ios
infrastructure 18.4
infrastructure 18.7
organisation iPhones
organisation UNC6353
organisation CVE-2025-43529
organisation CVE-2025-14174
infrastructure 18.6
infrastructure 26.3
infrastructure 18.7.3
infrastructure 26.2
infrastructure 18.7.2
infrastructure 26.1
organisation CVE-2025
organisation Apple
organisation PAC
organisation ANGLE
organisation CVE-2025-43510 - Memory
organisation CVE-2025-43520 - Memory
victims 20700 User mode
infrastructure 18.6.2
infrastructure 13.0
infrastructure 17.2.1
organisation CVE-2025-43510
organisation iVerify
organisation GPU
infrastructure 17.4.1
infrastructure 17.5.1
organisation HTML
organisation the DarkSword File Receiver
organisation OPSEC
organisation Springboard
organisation iFrame
organisation Lookout
organisation WebContent
organisation WebGPU
organisation SIM
organisation Telegram
organisation WhatsApp
‎at least November 2025
The threat actors used the DarkSword iOS exploit kit to target devices since at least November 2025.
infrastructure Ios
attribution Apple
attribution Google Threat Intelligence Group
source_region Saudi Arabia
source_region Malaysia
source_region Ukraine
attribution Threat Intelligence Group
tactic T1059.007 - JavaScript
attribution Telegram
attribution WhatsApp
attribution GHOSTKNIFE
attribution GHOSTSABER
‎late November 2025
DarkSword iOS Exploit Kit exploited vulnerabilities in 6 flaws and three zero-day exploits on devices running iOS 18.4-18.7, targeting a commercial surveillance vendor's devices associated with the PARS Defense company.
infrastructure Ios
infrastructure 18.4 iPhones
infrastructure 18.7 devices
‎December 2025
Threat actors used a combination of vulnerabilities in iOS versions 13 to 18.6.2, including UNC6353 and UNC6748 exploits, to target hundreds of millions of unpatched devices running these versions.
infrastructure Ios
infrastructure 18.4
infrastructure 18.7
infrastructure 18.6
organisation Google
general_metric 18.7 version
target_region Ukraine
source_region Russian Federation
tactic Espionage
infrastructure 18.6.2
‎March 2026
The GHOSTBLADE malware exploited six vulnerabilities and three zero-day exploits in the iOS DarkSword iOS Exploit Kit.
organisation GHOSTBLADE
‎2026/03/18
DarkSword attacks exploited multiple vulnerabilities in iOS devices.
target_region Saudi Arabia
infrastructure Ios
tactic T1059.007 - JavaScript
attribution Google Threat Intelligence Group
attribution Telegram
attribution WhatsApp
attribution GHOSTKNIFE
attribution GHOSTSABER
‎March 18
The DarkSide iOS exploit kit used six vulnerabilities and three zero-day exploits to target Apple devices.
attribution the Google Threat Intelligence Group
attribution BleepingComputer
‎the 2020s
Rocky Cole, co-founder and COO of iVerify, used poor operational security (OPSEC) practices to target devices in the 2020s.
organisation COO
‎2026/03/19
DarkSword targets iPhones running iOS 18.4 through 18.7 and is linked to multiple actors, including UNC6353, suspected to be Russian who used the Coruna exploit chain.
organisation Google
infrastructure Ios
organisation UNC6353
organisation DarkSword
infrastructure 18.4 iPhones
organisation Lookout
infrastructure 18.4
infrastructure 18.7
organisation iPhones
organisation iVerify
organisation CVE-2025-43529
organisation CVE-2025-31277
organisation CVE-2025-43510
organisation ANGLE
organisation OPSEC
organisation the Future of iOS
infrastructure 18.7.6
infrastructure 26.3.1
victims 200 users
organisation Apple
organisation Exploit Chain
infrastructure 18.6
organisation CVE-2025
organisation the Data Flow Graph
infrastructure 18.6 devices
infrastructure 18.7.3
infrastructure 26.2
organisation HTML
organisation UNC6748
organisation AES
organisation Local Privilege Escalation and
organisation XNU
organisation VFS
organisation WebKit
organisation GHOSTSABER
organisation GHOSTKNIFE
organisation Thieves Alike
organisation PAC
organisation Pointer Authentication Codes
organisation CVE-2025-14174
organisation WebGL
organisation GPU
organisation WebContent
organisation Less Lucrative Ransomware Market Makes
organisation AttackIQ
organisation GHOSTBLADE
organisation Apple Health
organisation Calendar Notes Installed
organisation The Red Report 2026
organisation RCE
organisation Project Zero
organisation API
organisation Webpack
Tactical Metrics
Metrics
infrastructure
​Ios
Affected Product
Metrics
infrastructure
​18.4
Software Version
Metrics
infrastructure
​18.7
Software Version
Metrics
infrastructure
​18.6
Software Version
Metrics
infrastructure
​26.3
Software Version
Metrics
infrastructure
​18.7.3
Software Version
Metrics
infrastructure
​26.2
Software Version
Metrics
infrastructure
​18.7.2
Software Version
Metrics
infrastructure
​26.1
Software Version
Metrics
victims
20,700
User Mode
Metrics
infrastructure
​18.6.2
Software Version
Metrics
infrastructure
​13.0
Software Version
Metrics
infrastructure
​17.2.1
Software Version
Metrics
infrastructure
​17.4.1
Software Version
Metrics
infrastructure
​17.5.1
Software Version
Metrics
infrastructure
​18.7.6
Software Version
Metrics
infrastructure
​26.3.1
Software Version
Metrics
victims
200,000,000
Users
Metrics
infrastructure
18
Iphones
Metrics
infrastructure
19
Devices
Metrics
infrastructure
19
Devices