UNC6353 is a suspected Russian espionage threat actor associated with watering-hole operations targeting Ukrainian users, particularly through compromised Ukrainian websites. The group has been linked to use of the Coruna iOS exploit kit and later adoption of the DarkSword full-chain iOS exploit framework beginning in late 2025, with activity continuing into 2026. Reporting consistently characterizes the actor as Russian-linked and aligned with espionage objectives, with some assessments noting overlap between intelligence collection and financially oriented theft. UNC6353 has targeted Ukrainian organizations and users across commercial and local-service contexts, including industrial vendors, retail or e-commerce entities, local services, court-related sites, and regional news outlets in the Donbas area. Its operations have relied heavily on watering-hole delivery, including compromise of legitimate websites and injection of malicious script tags or hidden iframes to selectively exploit visiting iPhone users. In DarkSword operations, UNC6353 used a browser-based exploit chain against vulnerable iOS versions to achieve full device compromise and deploy post-exploitation malware such as GHOSTBLADE. The malware and associated modules have been described as capable of stealing communications data, browser artifacts, credentials, keychain material, Wi-Fi data, location history, photos, health data, iCloud-related data, and cryptocurrency wallet information, followed by rapid exfiltration and cleanup to reduce forensic visibility. The actor has therefore demonstrated capabilities spanning initial access, credential and data theft, post-exploitation collection, exfiltration, and defense evasion. UNC6353 is distinct from TA446/SEABORGIUM and has separately been identified by multiple researchers as one of several actors using proliferated commercial or leaked iOS exploit tooling. The group is notable for combining high-end mobile exploitation with opportunistic website compromise in support of targeted collection against Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
30 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
19 CVEs this actor has used in observed campaigns. 19 of them exploited in the wild.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
14 more CVEs tied to this actor tracked in Mallory.
64 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a threat actor that may have used both the Coruna and DarkSword iOS exploit kits in attacks targeting Ukraine.
Named activity cluster mentioned as potentially linked through co-residence of Coruna and DarkSword infrastructure; not the primary focus of the article.
Associated with delivery of the Coruna iOS exploit kit against Ukrainian targets and described here as part of the DarkSword/Coruna proliferation lineage, with operators now using DarkSword infrastructure and GHOSTBLADE-enabled exploitation workflows.
A suspected Russian espionage group observed using the Coruna exploit kit previously and more recently incorporating the DarkSword iOS exploit chain into watering hole campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.