DarkSword: iOS Exploit Kit Leverages 6 Vulnerabilities, Including 3 Zero-Days, for Complete Device Control.
Mar 19, 2026 // 12:23 - Norina Velotta


Reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout indicate that a new exploit toolkit targeting Apple iOS, designed for data theft, has been used by various malicious entities since at least November 2025.

GTIG states that multiple surveillance companies and suspected state-backed actors have been using the DarkSword exploit kit in separate campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine.

DarkSword is the second iOS exploit kit to be discovered in a month, following Coruna. It’s designed for iPhones running iOS 18.4 to 18.7 and is believed to have been used by a Russian espionage group UNC6353 in attacks against Ukrainian users.

UNC6353 has also been associated with using Coruna against Ukrainians by injecting JavaScript into compromised websites.

Lookout says that “DarkSword seeks a vast amount of personal data, including login credentials, targeting numerous crypto wallets, suggesting a financially motivated attacker.” They also noted that “DarkSword collects targeted data from the device very quickly, then cleans up.”

Exploit chains like Coruna and DarkSword allow complete access to a victim’s device with minimal user interaction. These findings illustrate a market where threat groups with limited resources can acquire high-end exploits to infect mobile devices, even if their goals don’t align with cyber espionage.

GTIG stated, “The use of both DarkSword and Coruna by a variety of actors demonstrates the ongoing risk of exploit proliferation across actors of varying geography and motivation.”

The exploit chain linked to the new kit utilizes six vulnerabilities to deploy three payloads, including CVE-2026-20700, CVE-2025-43529, and CVE-2025-14174, which were exploited as zero-days before being patched by Apple:

  • CVE-2025-31277 – Memory corruption in JavaScriptCore (Fixed in version 18.6)
  • CVE-2026-20700 – PAC bypass in dyld (Fixed in version 26.3)
  • CVE-2025-43529 – Memory corruption in JavaScriptCore (Fixed in versions 18.7.3 and 26.2)
  • CVE-2025-14174 – Memory corruption in ANGLE (Fixed in versions 18.7.3 and 26.2)
  • CVE-2025-43510 – Memory Management in the iOS kernel (Fixed in versions 18.7.2 and 26.1)
  • CVE-2025-43520 – Memory corruption in the iOS kernel (Fixed in versions 18.7.2 and 26.1)

Lookout discovered DarkSword while analyzing malicious infrastructure linked to UNC6353. They found that a compromised domain hosted a malicious iFrame that loaded JavaScript to identify devices and determine if they should be directed to the iOS exploit chain. The method of website infection is currently unknown.

The JavaScript specifically targeted iOS devices running versions 18.4 to 18.6.2, unlike Coruna, which targeted older iOS versions (13.0 to 17.2.1).

Lookout explained that “DarkSword is a complete JavaScript exploit chain and data stealer. It uses several vulnerabilities to gain high-level code execution and access sensitive information for exfiltration.”

Like Coruna, the attack begins when a user visits a web page with a JavaScript-embedded iFrame via Safari. Once running, DarkSword can escape the WebContent sandbox (Safari’s renderer process) and use WebGPU to inject into mediaplaybackd, a system daemon for media playback.

This allows the data miner malware, GHOSTBLADE, to access privileged processes and restricted file system areas. After gaining higher privileges, an orchestrator module loads additional components to gather sensitive data and inject an exfiltration payload into Springboard, sending the collected data to an external server via HTTP(S).

This includes emails, iCloud Drive files, contacts, SMS messages, Safari browsing history and cookies, cryptocurrency wallet and exchange data, usernames, passwords, photos, call history, Wi-Fi configuration and passwords, location history, calendar data, cellular and SIM information, installed apps, data from Apple apps like Notes and Health, and message histories from apps like Telegram and WhatsApp.

iVerify stated that DarkSword utilizes JavaScriptCore JIT vulnerabilities in the Safari renderer, either CVE-2025-31277 or CVE-2025-43529 depending on the iOS version, to achieve remote code execution via CVE-2026-20700. It then escapes the sandbox via a GPU process, exploiting CVE-2025-14174 and CVE-2025-43510.

Finally, a kernel privilege escalation flaw (CVE-2025-43520) is used to gain arbitrary read/write and arbitrary function call abilities inside mediaplaybackd, ultimately executing the injected JavaScript code.

Lookout said, “This malware is very advanced and appears to be a professionally designed platform that permits rapid module development because of its high-level programming language. This extra care highlights the effort that was put into the development of this malware with sustainabilty, long-term development, and extensibility.”

Analysis of DarkSword’s JavaScript files found references to iOS versions 17.4.1 and 17.5.1, implying that the kit was adapted from an earlier version that targeted older operating system versions.

DarkSword is unique in that it isn’t designed for persistent surveillance; after data exfiltration, it cleans up staged files and exits. Lookout noted that its goal is to minimize dwell time and swiftly exfiltrate data.

Little is known about UNC6353 except that it uses both Coruna and DarkSword via watering hole attacks on compromised Ukrainian websites. The group likely has sufficient funds to acquire high-quality iOS exploit chains possibly created for commercial surveillance and may be considered a technically less sophisticated threat actor that operates with motives aligned with Russian intelligence requirements.

Lookout stated that “Given that both Coruna and DarkSword have capabilities for cryptocurrency theft and intelligence gathering, we must consider the possibility that UNC6353 is a Russia-backed privateer group or criminal proxy threat actor.”

The complete lack of obfuscation in DarkSword code and HTML for the iframes, combined with the straightforward design and naming of the DarkSword File Receiver, suggests that UNC6353 lacks strong engineering resources or does not prioritize operational security measures.

DarkSword’s use has also been connected to two other threat actors:

  • UNC6748, which targeted Saudi Arabian users in November 2025 with a Snapchat-themed website, snapshare[.]chat, employing the exploit chain to deliver the GHOSTKNIFE JavaScript backdoor capable of information theft.
  • PARS Defense, a Turkish commercial surveillance vendor, which used DarkSword in November 2025 to deliver GHOSTSABER, a JavaScript backdoor that communicates with an external server to facilitate device and account enumeration, file listing, data exfiltration, and arbitrary JavaScript code execution.

Google noted that UNC6353’s use of DarkSword in December 2025 only supported iOS versions 18.4 to 18.6, while iOS 18.7 devices have also associated with the UNC6748 and PARS Defense use observed..

iVerify said, “For the second time in a month, threat actors have employed waterhole attacks to target iPhone users,” adding that neither attack was specifically targeted, and the attacks now likely affect hundreds of millions of unpatched devices running iOS versions from 13 to 18.6.2.

“In both cases, the tools were found due to significant operational security failures and careless deployment of iOS offensive capabilities. These recent events prompt several key questions: How big and how well-funded is the market for iOS 0-day and n-day exploits for iOS devices? How accessible are such powerful capabilities to financially motivated actors?”

#“darksword”  #complete  #control  #device  #exploit  #for  #including  #ios  #kit:  #leverages  #news  #vulnerabilities  #zero-days   —   News