UNC6748 is a threat cluster associated with targeted exploitation of Apple iOS devices through the DarkSword exploit kit beginning in November 2025. It was the first observed user of DarkSword and conducted attacks against users in Saudi Arabia through a Snapchat-themed impersonation site that triggered exploitation in Safari. Post-compromise activity linked to UNC6748 involved deployment of the GHOSTKNIFE JavaScript backdoor. UNC6748 has been linked to use of a full-chain iOS exploitation capability affecting iOS 18.4 through 18.7 and enabling complete device compromise. The DarkSword chain combined six vulnerabilities to achieve remote code execution, sandbox escape, privilege escalation, and kernel-level access. Malware associated with UNC6748 was capable of exfiltrating signed-in account data, messages, browser data, location history, and microphone recordings. Reporting also notes anti-forensic behavior including deletion of crash logs and short-lived post-exploitation activity designed to reduce forensic visibility. The cluster has been described as a customer of the Turkish commercial surveillance vendor PARS Defense, indicating access to commercial spyware or exploit-as-a-service capabilities rather than an independently attributed nation-state program. High-confidence reporting directly ties UNC6748 to Saudi Arabia-focused mobile surveillance operations and to delivery of GHOSTKNIFE via phishing or impersonation infrastructure. Broader geopolitical attribution beyond that relationship is not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
DarkSword is an exploit kit that targets iPhones running iOS versions 18.4 through 18.7... The kit leverages six vulnerabilities, CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.
1 more CVE tied to this actor tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with use of the DarkSword exploit kit in attacks against iPhones and iPads running vulnerable iOS 18 versions.
Used the DarkSword iOS exploit kit in attacks against iPhones running vulnerable iOS 18 versions.
Group associated with DarkSword delivery through a fake Snapchat-themed website targeting users in Saudi Arabia and other countries.
Linked to use of the DarkSword iOS exploit kit in attacks involving cryptocurrency theft and surveillance activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.