Back Streetinsider Lookout Uncovers DarkSword iOS Exploit Chain, Exposing a New Era of Mobile Threats
Worldâs Largest Mobile Threat Intelligence Dataset Powers Discovery of Hit-and-Run Exploit Targeting iOS Users and Cryptocurrency Assets
BOSTON--(BUSINESS WIRE)-- Lookout, Inc., the leader in mobile security, today announced the discovery of DarkSword , a sophisticated, full iOS exploit chain and infostealer that signals a new phase in mobile threatsâwhere advanced exploit capabilities are increasingly leveraged for financial gain, and where AI is dramatically accelerating the scale and precision of these attacks.
Discovered by Lookout Threat Labs , DarkSword targets iPhones running iOS versions 18.4 through 18.6.2, using a âhit-and-runâ technique to rapidly exfiltrate highly sensitive dataâincluding credentials and cryptocurrency walletsâwithin minutes before erasing its presence to evade detection.
The investigation was conducted in collaboration with Google and iVerify , with Lookout contributing independent research and mobile threat analysis throughout the effort. Building on UNC6353 infrastructure previously reported by Google, Lookout researchers significantly advanced the characterization of the DarkSword campaign by analyzing the attacker's malicious infrastructure and the sophisticated data exfiltration modules. By identifying the command-and-control (C2) servers and the specific "hit-and-run" logic used to lift sensitive credentials and cryptocurrency wallets, Lookout uncovered the critical mobile security intelligence necessary to map the campaignâs true scope and financially motivated intent.
Building on previously reported UNC6353 infrastructure, Lookout researchers helped to advance the understanding of the DarkSword exploit chain and its broader operational context. The companyâs mobile security visibility and research expertise routinely support the identification and analysis of sophisticated mobile threats, providing important context for assessing campaigns such as those associated with UNC6353 â a well-funded, likely Russian-linked threat actor. This collaboration highlights the value of combining platform intelligence, and mobile-focused threat research to expose increasingly sophisticated mobile attacks.
A Breakthrough in Mobile Intelligence, Not Just Malware Discovery
DarkSword is not just another exploitâit is evidence of a structural shift in the mobile threat landscape.
Mobile devices have become the primary control plane for identity, access, and financial assets, making them the most valuableâand least instrumentedâattack surface in the enterprise. DarkSword demonstrates how quickly attackers can weaponize that gap.
âDarkSword represents a notable shift that we've predicted for years,â said Justin Albrecht, global director of mobile threat intelligence at Lookout. âAdvanced mobile malware has ceased to be a tool wielded solely by governments for espionage and is now in the hands of groups seeking financial gain. Between the rise in social engineering attacks targeting mobile devices and the availability of tools like DarkSword, it's time to take mobile security seriously and ensure that security teams have visibility into the increasing volume of threats targeting their mobile endpoints.â
the DarkSword Exploit
DarkSword is a highly engineered exploit chain leveraging vulnerabilities in Safari and WebGPU to escape the iOS sandbox and execute privileged code. Once deployed, it rapidly collects and exfiltrates:
Its âhit-and-runâ design minimizes dwell time, allowing attackers to extract high-value data and disappear before traditional detection methods can respond.
Lookout customers are protected against DarkSword through Safe Browsing and Device Compromise Detection, and we strongly advise all organizations to update to the latest iOS versions (â¥18.7.3 or â¥26.3) and retire unsupported devices.
Mobile Risk is Business Risk
DarkSword underscores a critical truth: the enterprise perimeter has shifted to mobile. Yet most organizations still rely on security models built for endpoints and networksânot the always-on, identity-rich, user-driven nature of mobile devices.
âThe emergence of exploit chains like DarkSword highlights a shift in the mobile threat landscape, with attacks requiring little to no user interaction,â said Mike Jude, Research Director at IDC. âAs mobile devices serve as gateways to both personal and enterprise data, mobile risk has become business risk and organizations must recognize that traditional security approaches are insufficient. To reduce exposure, organizations should have proactive mobile security, including monitoring, device management, and rapid patching.â
Lookout closes this gap with mobile endpoint detection and response (EDR) powered by the industryâs most comprehensive mobile datasetâgiving security teams the visibility and control required to defend against modern, cross-platform threats.
The Lookout Intelligence Advantage
Lookoutâs ability to uncover DarkSword is rooted in a fundamentally different approach to securityâone built on continuous, AI-driven mobile intelligence, not episodic analysis.
Lookout is the recognized leader in mobile security, trusted by governments, enterprises, and small businesses worldwide. The company pioneered the mobile security industry in 2009 and has built the largest and most advanced dataset in the market, protecting over 235 million devices and analyzing over 400 million apps. Powered by AI-driven mobile threat intelligence and supported by a world-class research team, Lookout delivers unmatched protection and proactive threat detection.
Â
View source version on businesswire.com :
Lookout PR: [email protected]
Source: Lookout, Inc.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
