A new version of iPhone exploit kit DarkSword has been leaked on GitHub; iVerify co-founder Matthias Frielingsdorf says the exploits “will work out of the box”
DarkSword was identified days earlier by Google, iVerify, and Lookout as a tool used against iOS 18 through Ukrainian websites. The GitHub leak changes that previously identified targeted capability from a researched threat into code that may be more broadly accessible.
The reported claim that the updated exploits work immediately raises the urgency for iPhone defenders and Apple. It also fits a longer record of actively exploited iOS zero-days requiring vendor patches.
First-order effects
The leaked kit gives additional actors access to DarkSword’s iPhone-targeting exploits, with iVerify’s co-founder warning they can be used without substantial modification.
Organizations and individuals responsible for iPhones face a more immediate need to identify potentially exposed devices and apply any available protections; Apple faces pressure to assess the leaked version’s reach.
Second-order effects
A public, usable kit lowers the operational barrier between a targeted exploitation technique and wider abuse, increasing the burden on mobile-security teams to detect related activity.
Security researchers and platform defenders can inspect the leaked material, potentially improving detection and remediation—but that defensive benefit arrives alongside broader attacker access.
Third-order effects
If high-end mobile exploit tooling continues to leak in usable form, the advantage from discovering an iOS exploit may erode faster, shifting more value toward rapid patching, detection, and device-response capabilities.
The episode reinforces a recurring mobile-security pattern: sophisticated iPhone compromise is not confined to its original operators once exploit details or code escape into public channels.
The trend: DarkSword is one instance of advanced mobile exploitation becoming more consequential when targeted tooling is redistributed beyond its original operators.
DarkSword payloads have surfaced and appear to be a full iOS 18.4 staged chain with WebContent RCE, SB escape, a kernel PE/KRW bundle, and post-exploit logic for task ops, process injection, and data collection. Not going to publicly link the payloads. Legit researchers can DM me
For the first time in over two years, there is set to be a new kernel exploit for up to iOS/iPadOS 18.7.1 and 26.0.1 - including the latest EoL versions for 15.x (presumed)/16.x/17.x. [Note: Just like the Coruna kit chain a few weeks ago, stuff here is subject to
You really gotta watch this space. I might be wrong, but feels like we're watching a wave starting to crest. Could see mass takeover of old/unpatched iPhones in a way we've never seen before. [embedded post]
@lorenzofb Lorenzo Franceschi-Bicchierai on bluesky
SCOOP: Someone has found new samples of the iPhone spyware DarkSword and published them on GitHub, putting millions of iOS users at risk. — A cybersecurity researcher told us that the leaked spyware is “way too easy to repurpose” and “we need to expect criminals and others to s…
NEW: Someone has publicly leaked an exploit toolkit called DarkSword, which allows any hacker or cybercriminal to easily hack iPhones and iPads running iOS 18. — Apple said it is aware & has issued patches. Security researchers have already tested the code as working. — w/ @…