Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionageendpoint-software-vulnerabilityinitial-access-methodwidely-deployed-product-advisory

DarkSword iOS Exploit Chain Used in Watering-Hole Attacks Against Ukrainians

Updated 3mo agoFirst seen Mar 18, 202654 sources

Researchers from Google, iVerify, and Lookout disclosed DarkSword, a sophisticated iPhone exploit chain used in compromised websites to silently infect visitors, with observed targeting focused on Ukraine and additional activity tied to Saudi Arabia, Turkey, and Malaysia. The campaign is linked to suspected Russian operators, including activity tracked as UNC6353, and appears to support both espionage and financial theft, including the theft of saved passwords, text messages, and cryptocurrency wallet data. Reporting also indicates DarkSword is the second major iOS exploit kit recently found in the wild after Coruna, reinforcing concerns that advanced mobile exploitation is becoming more broadly operationalized rather than reserved for narrowly targeted, bespoke use.

Technical analysis shows DarkSword used multiple chained vulnerabilities to achieve full device compromise on older iOS versions, including JavaScriptCore bugs CVE-2025-31277 and CVE-2025-43529 for remote code execution, CVE-2026-20700 as a dyld PAC bypass, and sandbox escapes that pivoted from WebContent to the GPU process and then to mediaplaybackd. The exploit chain relied on first compromising WebKit and then abusing WebGPU/ANGLE-related paths to escape Safari’s sandbox, and Apple patched the flaws across later iOS releases including 18.6, 18.7.3, 26.2, and 26.3. Researchers warned that a substantial installed base of devices running iOS 18 or earlier remained exposed at the time of disclosure, making DarkSword notable both for its technical sophistication and for the scale of potentially vulnerable iPhones.

Share:
DarkSword iOS Exploit Chain Used in Watering-Hole Attacks Against Ukrainians
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Apr 1, 20263mo ago

Apple releases iOS 18.7.7 and iPadOS 18.7.7 for DarkSword

On 2026-04-01, Apple issued iOS 18.7.7 and iPadOS 18.7.7 to protect older devices that had not upgraded to iOS 26 from the DarkSword exploit chain. Apple said devices already running iOS 26 were protected and expanded the iOS 18 fix so more legacy devices could receive it automatically.

Apple Issues Rare iOS 18 Security Update to Protect Against DarkSword Exploit - MacRumors
Mar 24, 20263mo ago

Working DarkSword exploit kit leaks on GitHub

By 2026-03-24, researchers warned that a functional DarkSword exploit kit had been leaked on GitHub. The leak was described as an escalation that could let lower-skilled attackers launch DarkSword attacks at scale against still-vulnerable iPhones and iPads.

DarkSword iPhone Exploit Leaked Online, Hundreds of Millions at Risk
Mar 23, 20263mo ago

CISA orders federal agencies to patch DarkSword iOS flaws

On 2026-03-23, CISA added three DarkSword-linked iOS vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered Federal Civilian Executive Branch agencies to remediate them by 2026-04-03 under Binding Operational Directive 22-01. The directive followed public reporting that the flaws were actively exploited in DarkSword attacks.

CISA orders feds to patch DarkSword iOS flaws exploited attacks
Mar 18, 20263mo ago

Researchers publicly disclose DarkSword and technical analysis

On March 18, 2026, Google, Lookout, and iVerify publicly disclosed DarkSword, describing a full-chain Safari-based iOS exploit and associated malware families GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. Their reports detailed the six-vulnerability chain, links to Coruna-related infrastructure, and attribution to multiple threat actors including UNC6353.

Google adds DarkSword delivery domains to Safe Browsing

After identifying the campaign infrastructure, Google added DarkSword delivery domains to Safe Browsing to help block access to malicious exploit sites. This was part of the defensive response alongside vulnerability disclosure to Apple.

Mar 11, 20263mo ago

Apple issues March 11 iOS 15 and 16 updates against Coruna and DarkSword

On 2026-03-11, Apple released security updates for supported iOS 15 and 16 devices and warned users that outdated iPhones remained vulnerable to the Coruna and DarkSword exploit kits. Apple said fully updated supported devices are protected and that Lockdown Mode can block these attacks even on older systems.

Apple urges iPhone users to update as Coruna and DarkSword exploit kits emerge
Feb 1, 20265mo ago

Apple rolls out patches for DarkSword exploit chain

Apple patched the vulnerabilities used by DarkSword across a series of iOS updates released from late 2025 through February 2026, with complete remediation available by iOS 26.3 and corresponding iOS 18 security updates. The fixes covered the six-flaw chain used for remote code execution, sandbox escape, PAC bypass, and kernel compromise.

Dec 1, 20257mo ago

DarkSword observed in campaigns beyond Ukraine

Researchers observed DarkSword used by multiple actors against targets in Saudi Arabia, Turkey, and Malaysia in addition to Ukraine. Reported operators included UNC6748 and customers of Turkish surveillance vendor PARS Defense.

UNC6353 starts DarkSword watering-hole attacks on Ukrainians

Beginning in December 2025, suspected Russian-linked actor UNC6353 used compromised Ukrainian websites to deliver DarkSword to visitors, selectively targeting Ukrainian users. The campaign focused on rapid data theft from iPhones rather than persistent surveillance.

Google reports DarkSword vulnerabilities to Apple

Google Threat Intelligence Group said it reported the vulnerabilities used in DarkSword to Apple in late 2025. This disclosure started Apple's remediation process for the exploit chain.

Nov 1, 20258mo ago

DarkSword exploitation begins against vulnerable iPhones

Researchers said the DarkSword iOS exploit kit has been used since at least November 2025 against iPhones running affected iOS 18 versions. The framework was used by multiple actors and enabled rapid theft of sensitive data, including credentials and cryptocurrency wallet information.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

130 LINKEDOpen in app
Vulnerabilities
31 linked
Memory corruption in Apple WebKit/JavaScriptCore web content processingOut-of-bounds memory access in ANGLE in Google Chrome on MacApple XNU VFS kernel race condition privilege escalationImproper locking copy-on-write memory corruption in Apple XNU kernelUse-after-free in Apple JavaScriptCore/WebKit leading to arbitrary code executionApple dyld user-mode PAC bypass and memory corruptionApple Multiple Products Integer Overflow or Wraparound VulnerabilityApple kernel memory protections bypass in iOS/iPadOS/macOS/tvOS/watchOS/visionOSKernel privilege escalation via integer overflow in Apple iOS/watchOS/macOSParallax kernel use-after-free in Apple iOS and iPadOSApple RTKit kernel memory protection bypassArbitrary Code Execution in Apple WebKit/JavaScriptCore Web Content ProcessingKernel memory disclosure in Apple iOS/macOS/watchOSNeutron kernel type confusion privilege escalation in Apple iOS/macOS/watchOSWebKit Use-After-Free in Apple Safari, iOS, iPadOS, and macOSApple WebContent Sandbox EscapeApple kernel sensitive state modification / PPL bypass in iOS and macOSWebKit Type Confusion Remote Code Executioncurl OAuth2 Bearer Token Leak on Cross-Protocol RedirectSame Origin Policy bypass in WebKit Navigation APIKernel sensitive state disclosure in Apple operating systemsWebKit cross-origin script message handler accessKernel memory disclosure in Apple Kernel loggingUse-after-free in AppleKeyStore802.1X authentication flaw allowing network traffic interceptionUse-after-free in Apple KernelWebKit Content Security Policy enforcement bypass via malicious web contentCross-site scripting in WebKitOut-of-bounds access in Apple CoreMedia audio stream processingKeychain access permissions flaw in Apple Security FrameworkActivation Lock bypass in iTunes Store path handling
Affected products
20 linked
IosIphoneSafariIpadosIpadTelegramWhatsappGithubIosAndroidWebkitAngleMetamaskKeybaseSignalIpad MiniImessageIcloudMacos TahoeMacos Sequoia
Organizations
61 linked
AppleGoogleLookoutGitHubTechCrunchiVerifyCnetPARS DefenseWIREDBinanceCoinbaseSnapLedgerKrakenMetamaskMatrix LLCMalwarebytesL3Harris TechnologiesOKXPhantom TechnologiesProofpointZDNETTrezorKuCoinUniswapSlashIDMEXCExodus MovementTrend MicroElectronic Frontier FoundationApproovBleepingComputerSamsung ElectronicsAccess NowSecurityWeekKasperskyRecorded FutureDark ReadingAtlantic CouncilMeta PlatformsFortinetJamfTelegramBloombergSafe Ecosystem FoundationAttackIQStatcounterCyberScoopNordstrom9to5MacTelemetryDeckThe New York Times CompanySecurity AffairsGizmodoAppleInsiderThe Hacker NewsSuzu LabsNews of DonbasApptunixGnosisMalfors
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

DarkSword iOS Exploit Chain Used in Watering-Hole Attacks Against Ukrainians | Mallory