ThreatCluster

DarkSword Exploit Kit Targets Millions of iPhone Users with Credential Theft

First seen 4 Aug 2026, 20:26 UTC CybersecuritynewsGbhackers 83% similarity 67

Article Content

Browse articles
ThreatCluster

The DarkSword exploit kit has emerged, leveraging a leaked iOS exploit chain to create a network of malicious web properties targeting iPhones running iOS 18.4 to 18.7. This campaign employs fake Apple ID login pages to steal sensitive user credentials and data. The exploit chain was initially disclosed by the Google Threat Intelligence Group and has since been linked to a fast-moving server cluster. Millions of iPhone users are at risk as the attack vector allows for seamless device compromise. The infrastructure reportedly spans 180 web properties and 27 hosts, indicating a broad scope of impact. Security experts are urging immediate action to mitigate the risks associated with this exploit kit.

Key Points: • DarkSword exploit kit targets iPhones running iOS 18.4 to 18.7. • The campaign uses fake Apple ID login pages to steal user credentials. • The malicious infrastructure includes 180 web properties and 27 hosts.

ThreatCluster AI How this analysis works

Timeline

2026-08-04
DarkSword exploit kit disclosed
The exploit kit combines iOS exploits with fake Apple ID login pages, risking millions of users.
Gbhackers
2026-08-04
DarkSword infrastructure identified
The exploit kit has expanded to 180 web properties and 27 hosts, targeting iPhones.
Cybersecuritynews

Community

Browse all →

Tracked Entities in This Story