A GitHub user published a newer version of iPhone exploit kit DarkSword; iVerify co-founder Matthias Frielingsdorf says the exploits “will work out of the box”
DarkSword was identified days earlier by Google, iVerify and Lookout as a tool used to target iOS 18 through Ukrainian websites. The publication of a newer build turns that previously investigated iOS-targeting tool into a more immediate defensive concern because its availability is no longer confined to the operators researchers tracked.
The report also fits a longer iOS security pattern: researchers have previously disclosed iOS flaws exploited in the wild before fixes were available. What is distinctive here is the claimed ease of use of a named exploit kit, rather than the discovery of a vulnerability alone.
First-order effects
People who obtain the published DarkSword build can assess and potentially use the kit without reproducing the original research; iVerify's “out of the box” assessment makes its practical usability the immediate question.
Organizations responsible for potentially affected iPhones must treat DarkSword as an available toolset, not only as a threat-research finding.
Second-order effects
Apple and mobile-security providers face pressure to validate exposure, prioritize detections and accelerate mitigations for the iOS 18 targeting technique associated with DarkSword.
GitHub becomes part of the incident-response surface: hosting and redistribution can determine how quickly a leaked exploit kit reaches additional actors, even if the original post is removed.
Third-order effects
If the kit proves broadly usable, iPhone compromise capability can move from specialized operators toward reusable tooling, shortening the gap between exploit disclosure and defensive action.
The episode reinforces the value of maintaining security support for older platform releases; the later backported patches for iOS 18 show how exploit availability can force protection beyond the newest software version.
The trend: This is one data point in the commoditization of mobile exploitation, where leaked operational tooling can turn targeted techniques into a wider patching and detection problem.
DarkSword payloads have surfaced and appear to be a full iOS 18.4 staged chain with WebContent RCE, SB escape, a kernel PE/KRW bundle, and post-exploit logic for task ops, process injection, and data collection. Not going to publicly link the payloads. Legit researchers can DM me
For the first time in over two years, there is set to be a new kernel exploit for up to iOS/iPadOS 18.7.1 and 26.0.1 - including the latest EoL versions for 15.x (presumed)/16.x/17.x. [Note: Just like the Coruna kit chain a few weeks ago, stuff here is subject to
You really gotta watch this space. I might be wrong, but feels like we're watching a wave starting to crest. Could see mass takeover of old/unpatched iPhones in a way we've never seen before. [embedded post]
Meanwhile we're locked into the worst of all worlds: — Devices that are locked down into a constant drag of forced obsolescence — AND — vulnerabilities. — So Apple, with essentially infinite resources, is the most erratic and unhelpful steward of technology we depend on. …
@lorenzofb Lorenzo Franceschi-Bicchierai on bluesky
SCOOP: Someone has found new samples of the iPhone spyware DarkSword and published them on GitHub, putting millions of iOS users at risk. — A cybersecurity researcher told us that the leaked spyware is “way too easy to repurpose” and “we need to expect criminals and others to s…
NEW: Someone has publicly leaked an exploit toolkit called DarkSword, which allows any hacker or cybercriminal to easily hack iPhones and iPads running iOS 18. — Apple said it is aware & has issued patches. Security researchers have already tested the code as working. — w/ @…