UNC6353 is a Russia-linked cyberespionage threat cluster tracked by Google Threat Intelligence Group that targets Ukrainian iPhone users through watering-hole attacks. Its operations have used compromised Ukrainian websites belonging to regional news organizations, local courts, industrial-equipment vendors, e-commerce businesses, and local-service providers. The cluster is distinct from TA446, also known as ColdRiver and Star Blizzard; no additional aliases or subgroups are established. UNC6353 has deployed both the Coruna and DarkSword iOS exploit kits, using Coruna before incorporating DarkSword into campaigns observed from late 2025 through March 2026. Coruna supports vulnerable devices running iOS 13.0 through 17.2.1, while DarkSword targets vulnerable versions of iOS 18.4 through 18.7. The actor injects malicious JavaScript into legitimate compromised websites, allowing visits by targeted users to initiate browser exploitation with minimal additional interaction. The exploit chains combine browser compromise, sandbox escape, and kernel privilege escalation to enable access to sensitive device data. Its DarkSword operations support credential theft and collection of messages, contacts, call histories, and other private information. The tooling emphasizes rapid exfiltration and removal of temporary artifacts rather than persistent access, enabling short-duration surveillance while reducing forensic evidence. Although the cluster is associated with Russian espionage activity, a specific sponsoring agency has not been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
19 CVEs this actor has used in observed campaigns. 19 of them exploited in the wild.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
14 more CVEs tied to this actor tracked in Mallory.
64 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously documented DarkSword operator mentioned as background to distinguish the newly observed, unattributed operator. The parenthetical Ukraine reference does not explicitly establish attacker origin or targeting.
Conducted suspected Russia-linked mobile espionage against Ukrainian users using compromised websites to deliver the DarkSword iPhone exploit kit and collect sensitive device data.
Suspected Russia-aligned mobile espionage activity targeting Ukrainian iPhone users through watering-hole compromises. The operation uses DarkSword to rapidly collect sensitive device data and remove traces.
Referenced as a threat actor that may have used both the Coruna and DarkSword iOS exploit kits in attacks targeting Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.