UNC6748 is a threat cluster associated with targeted iOS compromise using the DarkSword exploit kit. Its activity was first observed in early November 2025, targeting users in Saudi Arabia through a Snapchat-themed phishing website. Visiting the malicious site triggered browser exploitation automatically. UNC6748 has also been identified as a customer of Turkish commercial surveillance vendor PARS Defense; its country of origin and state sponsorship have not been established. UNC6748 used DarkSword to deploy GHOSTKNIFE, a JavaScript backdoor capable of exfiltrating signed-in account data, messages, browser data, location history, and microphone recordings. DarkSword chains browser exploitation, sandbox escapes, and privilege escalation to compromise vulnerable devices running iOS 18.4 through 18.7 and execute payloads with kernel-level privileges. Its post-exploitation framework injects JavaScript execution components into privileged iOS services. GHOSTKNIFE communicates with command-and-control infrastructure using a custom binary protocol encrypted with ECDH and AES, and deletes device crash logs to hinder forensic detection. UNC6748 is distinct from UNC6353, the suspected Russian espionage actor that separately deployed DarkSword against Ukrainian users.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
1 more CVE tied to this actor tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously documented DarkSword operator mentioned only for comparison with the newly observed cluster. The reference provides no specific operational details and does not clarify whether the Saudi Arabia association denotes origin or targeting.
Associated with use of the DarkSword exploit kit in attacks against iPhones and iPads running vulnerable iOS 18 versions.
Used the DarkSword iOS exploit kit in attacks against iPhones running vulnerable iOS 18 versions.
Group associated with DarkSword delivery through a fake Snapchat-themed website targeting users in Saudi Arabia and other countries.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.