DarkSword is a sophisticated commercial iOS full-chain exploit kit and spyware delivery framework targeting Apple devices running iOS and iPadOS 18.4 through 18.7. It has been observed since at least November 2025 in campaigns attributed to multiple commercial surveillance vendors and suspected state-sponsored operators, and later proliferated more broadly after a public leak enabled reuse by additional actors, including criminal operators.
DarkSword is delivered primarily through web-based compromise. Observed operations used watering-hole attacks on compromised sites, Apple-themed lure pages, fake sign-in portals, and other malicious landing pages that silently loaded hidden exploit content when visited from a vulnerable device. The chain combines six vulnerabilities to achieve remote code execution, sandbox escape, and privilege escalation, then deploys post-exploitation payloads including GHOSTBLADE and related modules.
Post-compromise behavior centers on surveillance and data theft. Reported capabilities include theft of keychain material, saved Wi-Fi credentials, iCloud data, photos, notes, messages, call history, contacts, browser-related data, authentication material, and cryptocurrency wallet data, followed by exfiltration to operator-controlled infrastructure. Some observed infrastructure also paired device exploitation with credential-harvesting decoys, including Apple ID phishing pages. Anti-forensics behavior has been reported, including deletion of crash artifacts and self-cleanup to reduce forensic visibility.
DarkSword has been linked to campaigns targeting victims in Saudi Arabia, Turkey, Malaysia, and Ukraine, and its spread across multiple unrelated operators has been compared to the earlier Coruna iOS exploit ecosystem. Public reporting has also associated DarkSword activity with watering-hole operations and at least one phishing campaign after the toolkit leaked. Apple issued patches and backported protections for affected users, and fully updated devices are not believed to remain vulnerable to the known chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Google, iVerify, and Lookout have all detailed DarkSword, a complex exploit chain used since November 2025 against iPhones running iOS versions 18.4 through 18.7... Attacker aims include achieving remote code execution (RCE), sandbox escape, and privilege escalation, ultimately leading to payload delivery... He also says DarkSword is designed to steal 'basically everything,' including keychain credentials, Wi-Fi passwords, iCloud data, photos and notes, and more.
Additionally, two vulnerabilities and a multi-component exploit kit were directly connected to active malware campaigns, including a sophisticated iOS full-chain exploit called DarkSword that delivered the GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE payloads.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
DarkSword is a fully weaponized iOS exploit kit, first identified in active campaigns as far back as November 2025 by Google’s Threat Intelligence Group (GTIG), iVerify, and Lookout. The toolkit specifically targets devices running iOS 18.4 through 18.7, leveraging a chain of six distinct vulnerabilities including bugs in JavaScriptCore, dyld, and the iOS sandbox to achieve full kernel-level code execution without any user interaction beyond a single website visit.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
DarkSword, discovered and detailed earlier this year by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, refers to a full-chain exploit kit that is believed to have been used by commercial surveillance vendors and suspected state-sponsored actors in disparate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine since at least November 2025.
In mid-March, when three cybersecurity firms — iVerify, Lookout, and Google’s Threat Intelligence Group — published coordinated findings about an exploit kit they named DarkSword. Researchers found it sitting openly on compromised Ukrainian websites... Any visitor on an unpatched iPhone running iOS 18.4 through 18.6.2 would have been silently compromised the moment the page loaded.
Apple has patched the vulnerabilities associated with the DarkSword exploit chain for all affected customers... DarkSword leaked to GitHub on March 22... We’ve observed a handful of campaigns being conducted with the malware, to include [an] email phishing campaign conducted by TA446 which spoofed the Atlantic Council.
A major new cybersecurity threat has emerged for iPhone users worldwide, as researchers have uncovered a new hacking tool called DarkSword. According to a joint investigation by Google, Lookout, and iVerify, hundreds of millions of people could be at risk if they have not updated their software recently.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The campaign targets iPhones running iOS 18.4 through 18.7 and is designed to steal highly sensitive data after a victim visits a lure site.
Load exploit chain : The iframe pulls the six-vulnerability DarkSword chain (kernel driver exploit, MIG filter bypass, PAC bypass, sandbox escape), targeting iOS 18.4 through 18.7.
Once compromised, according to Frielingsdorf, Coruna injected its code into legitimate system processes such as the power daemon and location daemon rather than running a dedicated spyware process, making detection more difficult.
T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion) ; Leurre : page AWS, iOS ou Apple ID impersonée
Once compromised, according to Frielingsdorf, Coruna injected its code into legitimate system processes such as the power daemon and location daemon rather than running a dedicated spyware process, making detection more difficult.
The operators also try to remove signs of compromise by deleting crash reports and RemoteLog.log before exiting.
The operators also try to remove signs of compromise by deleting crash reports and RemoteLog.log before exiting.
Once triggered, DarkSword can bypass protections, access device data...
iVerify researchers saw new variants with improved jailbreak and virtualization detection functionality...
The infrastructure included fake AWS console pages, Apple ID credential-harvesting pages, and other disposable lure fronts.
T1056.003 — Input Capture: Web Portal Capture (Collection) ; 103.106.190[.]217 : co-héberge le panel “C2 Control Panel” et une page de phishing Apple ID
He also says DarkSword is designed to steal "basically everything," including keychain credentials, Wi‑Fi passwords, iCloud data, photos and notes, and more.
A victim who reaches a malicious page is served a staging page that silently loads a hidden frame and selects exploit code based on the iOS version.
A DarkSword az érintett készülékeken személyes adatok (névjegyek, üzenetek, híváselőzmények, hitelesítéshez szükséges információk) megszerzésére képes
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A sophisticated iOS exploit chain/spyware framework used against iPhones to achieve RCE, sandbox escape, and privilege escalation, then deliver payloads and steal extensive device data including credentials, iCloud content, photos, notes, and cryptocurrency wallet data.
Named malware referenced as a topic of prior GTIG research/publication; no functional details are provided in the content.
A leaked six-vulnerability iOS exploit chain and exploit kit that uses malicious lure pages and hidden staging content to compromise iPhones, bypass protections, gain deeper device access, and deploy follow-on modules for data theft.
An iOS exploit kit / exploit chain used via malicious lure sites and compromised web properties to gain deeper access to targeted iPhones, bypass protections, and facilitate theft of sensitive device data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.