Snoops plant info-stealing malware on iPhones, Google warns

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Google, iVerify, and Lookout have jointly disclosed DarkSword, a new iOS exploit kit active since November 2025 that chains six CVEs to deploy three JavaScript backdoors (GhostKnife, GhostSaber, GhostBlade) capable of stealing messages, location history, cryptocurrency wallet data, recordings, and more. The kit is being abused by multiple threat actors including a suspected Russian espionage group (UNC6353) targeting Ukrainians, Turkish surveillance vendor PARS Defense targeting Turkish and Malaysian users, and UNC6748 targeting Saudi Arabians. All six exploited vulnerabilities have been patched, and users are urged to update to the latest iOS release. This is the second iOS exploit kit disclosed this month, following the earlier Coruna framework.

5m read timeFrom go.theregister.com
Post cover image
Table of contents
How the exploit chain worksWho is using DarkSword to spy on iPhone users?

Sort: