PARS Defense is a Turkish commercial surveillance vendor associated with exploitation of Apple iOS devices and deployment of spyware. Its surveillance tooling has been used in campaigns targeting users in Turkey and Malaysia, including operations conducted by its customers. PARS Defense has also been linked to exploitation of the iOS vulnerabilities CVE-2023-42916 and CVE-2023-42917. In late November 2025, PARS Defense-associated activity in Turkey used the DarkSword exploit kit against iPhones running iOS 18.4 through 18.7. Delivery included a fake Snapchat-themed website. DarkSword chains browser exploitation, sandbox escapes, and privilege escalation to obtain kernel-level access and inject code into privileged iOS processes. The Turkey campaign obfuscated exploit loaders and stages and protected exploit delivery using ECDH and AES encryption. PARS Defense-associated campaigns in Turkey and Malaysia deployed GHOSTSABER, a JavaScript backdoor supporting more than 15 command-and-control commands. Its capabilities include device and account enumeration, file listing and exfiltration, arbitrary JavaScript execution, SQLite queries, and photo-thumbnail uploads. Activity in Malaysia involved another PARS Defense customer using the same backdoor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
8 CVEs this actor has used in observed campaigns. 8 of them exploited in the wild.
CVE-2023-42916 and CVE-2023-42917 (Apple iOS) — PARS Defense.
CVE-2023-42916 and CVE-2023-42917 (Apple iOS) — PARS Defense.
CVE-2025-14174 sbox0_main_18.4.js , sbx0_main.js Out-of-bounds memory access in WebGL operation ANGLE (GPU process / WebKit) Yes iOS 18.7.3, 26.2
CVE-2025-31277 rce_module.js JIT optimization / type confusion JavaScriptCore (WebKit) No iOS 18.6
CVE-2025-43510 sbx1_main.js Memory management / copy-on-write bug XNU Kernel No iOS 18.7.2, 26.1
3 more CVEs tied to this actor tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Turkish commercial surveillance vendor mentioned as a previous operator of the DarkSword iOS exploit kit, using a fake Snapchat-themed website. The content does not attribute the P7 variant to this operator.
Named as a previously documented DarkSword operator, solely to distinguish it from the newly observed cluster. The Turkey/Malaysia association is not explicitly characterized as attacker origin or victim geography.
A Turkish commercial surveillance vendor using the DarkSword iOS exploit chain to deploy GHOSTSABER in surveillance campaigns targeting victims in Turkey and Malaysia.
Turkish commercial surveillance vendor associated with DarkSword activity in Turkey and Malaysia, using the exploit kit with stronger OPSEC and delivering the GHOSTSABER backdoor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.