CISA mandates immediate patching of actively exploited DarkSword iOS vulnerabilities on federal devices.
Mar 23, 2026 // 11:56 - Tristan Wall


The Cybersecurity and Infrastructure Security Agency (CISA) has directed U.S. federal agencies to apply patches for three iOS security weaknesses. These flaws are being actively exploited in cryptocurrency theft and cyberespionage campaigns through the DarkSword exploit kit.

According to a recent report by Google Threat Intelligence Group (GTIG) and iVerify researchers, the DarkSword framework exploits six vulnerabilities identified as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.

These security gaps enable attackers to bypass security sandboxes, elevate their access levels, and run malicious code remotely on iPhones that have not been updated. However, Apple has addressed these issues in the latest iOS updates, and now only iPhones running iOS versions 18.4 to 18.7 are vulnerable.

Security experts have associated DarkSword with several threat actors, including UNC6748, a client of the Turkish surveillance firm PARS Defense, and UNC6353, suspected to be a Russian espionage group.

GTIG observed that these attacks involved the deployment of three different information-stealing malware families: GhostBlade, a highly aggressive JavaScript-based tool; GhostKnife, a backdoor capable of extracting large amounts of data; and GhostSaber, a JavaScript-based malware that executes code and steals data.

UNC6353 was observed using both the DarkSword and Coruna iOS exploit kits in watering-hole attacks. These attacks targeted iPhone users visiting compromised Ukrainian websites related to e-commerce, industrial equipment, and local service providers.

DarkSword is designed to erase temporary files and terminate itself after exfiltrating data from compromised devices, indicating its design for limited surveillance operations meant to avoid detection.

Lookout, a mobile security company, discovered DarkSword and believes it is utilized in cyber-espionage campaigns supporting Russian intelligence objectives and by Russian threat actors motivated by financial gain. The discovery was made during investigations into infrastructure associated with the Coruna attacks.

On Friday, CISA added three of the six DarkSword vulnerabilities (CVE-2025-31277, CVE-2025-43510, and CVE-2025-43520) to its list of known exploited vulnerabilities, mandating that Federal Civilian Executive Branch (FCEB) agencies patch these issues within two weeks, by April 3, according to Binding Operational Directive (BOD) 22-01.

“Follow the vendor’s patching instructions, heed BOD 22-01 guidance for cloud services, or discontinue using the affected product if patches are unavailable,” CISA advised.

“These types of vulnerabilities are common pathways for cybercriminals to launch attacks, creating significant risks for the federal government.”

BOD 22-01 is only mandatory for federal agencies. However, CISA is encouraging security professionals from all sectors, including private companies, to address these vulnerabilities in their organizations’ devices promptly.

#“darksword”  #actively  #cisa  #devices  #exploited  #federal  #immediate  #ios  #mandates  #news  #patching  #vulnerabilities   —   News