Google, iVerify, and Lookout researchers discover DarkSword, a hacking tool used by Russia-sponsored and other hackers to target iOS 18 via Ukrainian websites
A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers.
The targeting of Ukrainian websites gives the discovery particular operational importance: sites used by a defined audience can become a delivery channel for device compromise without that audience seeking out malicious software.
First-order effects
iOS 18 users visiting the affected Ukrainian sites face an identified compromise route, while Google, iVerify, and Lookout can turn their findings into detection and mitigation work.
Apple and security teams must treat DarkSword as an active iPhone-targeting capability rather than a purely theoretical exploit chain.
Second-order effects
The disclosure raises the value of web-traffic monitoring and incident response for organizations serving Ukrainian audiences, since compromised legitimate sites can bypass users' normal caution around app downloads.
The risk can broaden if exploit tooling becomes easier to obtain; a later GitHub-published newer DarkSword version was described by iVerify's co-founder as usable out of the box.
Third-order effects
Apple's later decision to issue backported patches for iOS 18 suggests that targeted exploit campaigns can force support for older software branches when the affected installed base remains exposed.
If web-delivered iPhone exploit kits continue to circulate beyond their original operators, mobile security will increasingly depend on rapid cross-vendor research disclosure and patch deployment, not only platform hardening.
The trend: DarkSword is one data point in the growing operationalization of mobile exploit kits, where targeted web compromises can spread high-end iPhone intrusion capabilities beyond a single sponsor.
A second iOS exploit has been found in the wild, again used by Russian spies to infect websites and hack visitors' iPhones. This one works on iOS 18, and appeared in a very reusable form, so will likely proliferate. — If you haven't updated your iPhone, now's the time. www.wir…
This tool has already been used in distinct hacking campaigns against Ukrainians, Malaysians, Saudi and Turkish victims. If other hackers needed any more encouragement to adopt it, too, the Russian spies who used it left it fully unobfuscated with even its developers' helpful co…
NEW: iPhones running iOS 18—there are hundreds of millions of them—are potentially vulnerable to newly discovered hacking tools, capable of stealing troves of data, that were found in use in the wild. Update to iOS 26 now to patch. @agreenberg.bsky.social reports: www.wired.com/…
NEW: Joint research from Google, iVerify and Lookout uncovers “Darksword,” *another* suspected exploit kit built using high-end iOS exploits likely originally developed by/for the U.S. government. This is similar to Coruna, but has a much larger potential victim base cyberscoop.…
In collaboration with Lookout and Google (thank you 🙏) we have been working on tearing down and building detections for DarkSword - iOS exploit chain for iOS 18.4 - 18.7. Super excited for this research 🎉. Please update your iPhones. https://iverify.io/...
🗞️DarkSword, a full-chain iOS exploit using 4 zero-days, has been used in real attacks across multiple countries🥷🚀 Targets iOS 18.4-18.7, while earlier Coruna chains hit iOS 13-17.2.1. https://onejailbreak.com/... This may be useful for a jailbreak, and more! — All via Safari [im…
Interestingly, we haven't seen these surveillance payloads scoop up your interactions with AI apps. Some day soon, surely, as ChatGPT knows more about you than any contact on your device.
Two full iOS exploit kits in one month, deployed via watering holes on public websites, potentially affecting hundreds of millions of devices. Will Apple acknowledge that this no longer fits the “very small number of highly targeted individuals” narrative? [image]
Wild couple weeks for the iOS jailbreak community. 2 exploit chains in 2 weeks. ICYMI, there's a new iOS 18 chain (details below). Payloads don't appear to be in the wild, (good given how many are still on iOS 18), but likely means no imminent ability to adapt for a jailbreak.
As usual, Wired is... not great 🙄 — Regarding DarkSword, the latest objectively bad exploit affecting iOS and Safari, Google has a more in depth analysis, with a lot more informations on the specific versions of iOS that are affected. …
Hundreds of Millions of iPhones Can Be Hacked With a New Tool Found in the Wild | A powerful iPhone-hacking technique known as DarkSword has been discovered in use by Russian hackers. …