PARS Defense is a Turkish commercial surveillance vendor associated with targeted iOS intrusion activity using the DarkSword exploit chain and the GHOSTSABER post-exploitation malware family. Activity linked to PARS Defense was observed from late 2025 against users in Turkey, and later in Malaysia through another PARS Defense customer. The actor has been tied to exploitation of iPhones running affected iOS 18.4 through 18.7 versions, using a sophisticated full-chain compromise that achieved remote code execution, sandbox escape, privilege escalation, and kernel-level access. Operations associated with PARS Defense deployed GHOSTSABER, a JavaScript backdoor supporting more than 15 command-and-control functions. Reported capabilities include device and account enumeration, file listing, file exfiltration, arbitrary JavaScript execution, arbitrary SQLite query execution, and photo thumbnail collection, with some functions such as audio recording and real-time geolocation apparently enabled through additional runtime-downloaded modules. The associated campaigns demonstrated comparatively strong operational security, including obfuscation of exploit stages and encrypted delivery of exploit components. PARS Defense fits the profile of a commercial spyware or lawful-intercept vendor rather than a conventional state intelligence unit, but its tooling and operations are consistent with high-end surveillance activity directed at selected mobile users. Known associated tooling includes DarkSword and GHOSTSABER.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
CVE-2025-14174 sbox0_main_18.4.js , sbx0_main.js Out-of-bounds memory access in WebGL operation ANGLE (GPU process / WebKit) Yes iOS 18.7.3, 26.2
CVE-2025-31277 rce_module.js JIT optimization / type confusion JavaScriptCore (WebKit) No iOS 18.6
CVE-2025-43510 sbx1_main.js Memory management / copy-on-write bug XNU Kernel No iOS 18.7.2, 26.1
CVE-2025-43520 pe_main.js Kernel-mode race condition in VFS implementation XNU Kernel (Virtual Filesystem) No iOS 18.7.2, 26.1
CVE-2025-43529 rce_worker_18.6.js , rce_worker_18.7.js Use-after-free / garbage collection bug in DFG JIT layer JavaScriptCore (WebKit) Yes iOS 18.7.3, 26.2
1 more CVE tied to this actor tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Turkish commercial surveillance vendor using the DarkSword iOS exploit chain to deploy GHOSTSABER in surveillance campaigns targeting victims in Turkey and Malaysia.
Turkish commercial surveillance vendor associated with DarkSword activity in Turkey and Malaysia, using the exploit kit with stronger OPSEC and delivering the GHOSTSABER backdoor.
Observed leveraging the DarkSword iOS exploit chain in a campaign in Turkey.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.