THREAT_INTEL

Latest Edition
DarkSword iPhone Spyware Exposed. Russia-Linked Group Weaponized Ukrainian Websites to Silently Compromise 220 Million Vulnerable Devices
EDITION #042026-03-19

DarkSword iPhone Spyware Exposed. Russia-Linked Group Weaponized Ukrainian Websites to Silently Compromise 220 Million Vulnerable Devices

A full-chain iOS exploit called DarkSword has been silently compromising iPhones since November 2025, deployed through watering hole attacks on Ukrainian news and government websites by the Russia-linked group UNC6353. The exploit chains six zero-day vulnerabilities to achieve kernel privileges and deploys three malware families that steal everything from crypto wallets to iCloud data before self-destructing within minutes. An estimated 220 million iPhones running iOS 18.4 through 18.7 were in the blast radius.

DarkSwordiOS-exploitzero-clickwatering-holeiPhoneUNC6353
Read Full Digest
Previous Editions

Stay current on active threats

New intel reports on active threats, CVEs, and emerging attack vectors — curated by 4nuxd.

Get in touch