“Darksword” iOS exploit infects iPhones in infostealer attack. Data theft via new vulnerability.
Mar 18, 2026 // 18:17 - Niko Dunn


A newly discovered exploit kit and delivery system called “DarkSword” has been employed to pilfer a wide array of personal details, including information from a cryptocurrency wallet application.

DarkSword focuses on iPhones operating iOS versions 18.4 to 18.7 and is associated with several malicious entities, including the one that utilized the Coruna exploit chain revealed earlier in June.

Researchers at Lookout Threat Labs came across DarkSword while probing the infrastructure used for the Coruna attacks. Google’s Threat Intelligence Group and iVerify also collaborated to perform a more thorough examination of this previously unknown threat and its operators.

iVerify’s research suggests that all vulnerabilities exploited in this chain are already publicly known or documented, and Apple has already patched them in the most recent iOS updates.

The DarkSword toolkit exploits six security flaws recognized as CVE-2025-31277, CVE-2025-43529, CVE-2026-20700, CVE-2025-14174, CVE-2025-43510, and CVE-2025-43520.

While the responsible party remains unidentified, the threat actor utilizing DarkSword is designated as UNC6353, and they appear to be well-resourced and possess access to various known and unknown exploits.

The researchers observed evidence of large language model (LLM) technologies enhancing DarkSword’s capabilities, however, they emphasize that the malware itself is quite sophisticated and not a simple AI-generated tool.

“This malware exhibits a high level of sophistication and seems to be a professionally built platform that allows for swift module development via a high-level programming language,” Lookout notes in their report.

“This additional undertaking demonstrates a considerable commitment to the malware’s development, taking into account maintainability, long-term growth, and adaptability.”

Besides the 1-click DarkSword exploit kit, iVerify discovered a Safari exploit with “sandbox bypass, privilege elevation, and in-memory implants” that exfiltrated sensitive information from devices.

DarkSword attacks commence within the Safari browser, leveraging multiple exploits to gain kernel read/write privileges, and then executing code via a primary orchestrator component (pe_main.js).

The initial compromise of the websites used to launch these attacks is unknown, but the malicious actors had sufficient permissions to inject malicious iframes into the HTML code of these sites.

The orchestrator injects a JavaScript engine into iOS services with elevated privileges such as App Access, Wi-Fi, Springboard, Keychain, and iCloud, subsequently activating modules designed for data theft.

According to Lookout’s analysis, DarkSword targets the following information:

  • Saved passwords
  • Photos, including screenshots and hidden image files
  • WhatsApp and Telegram databases
  • Cryptocurrency wallets (Coinbase, Binance, Ledger, and others)
  • Text messages (SMS)
  • Address book
  • Call history
  • Location history
  • Browser history
  • Cookies
  • Wi-Fi history and passwords
  • Apple Health data
  • Calendar
  • Notes
  • Installed applications
  • Connected accounts

Importantly, DarkSword clears temporary files and quits upon successful exfiltration of the aforementioned items, signifying that it’s not intended for sustained surveillance.

Lookout suggests that DarkSword is operated by a Russian threat actor focusing on financial gain, alongside espionage activities aligned with Russian intelligence requirements.

iPhone users are advised to update to iOS 26.3.1 (the latest version), released earlier in June, and activate Lockdown Mode if they believe they are at a heightened risk of malware targeting.

For those using older devices that cannot be updated to the newest iOS release, Apple might provide backported fixes as they did with the Coruna exploits, but this has not yet been officially confirmed.

#“darksword”  #attack  #data  #exploit  #infects  #infostealer  #ios  #iphones,  #new  #news  #theft  #via  #vulnerability   —   News