DarkSword Exploit Kit Targets Millions of iPhone Users with Credential Theft
Article Content
- •DarkSword exploit kit targets iPhones running iOS 18.4 to 18.7.
- •The campaign uses fake Apple ID login pages to steal user credentials.
- •The malicious infrastructure includes 180 web properties and 27 hosts.
The DarkSword exploit kit has emerged, leveraging a leaked iOS exploit chain to create a network of malicious web properties targeting iPhones running iOS 18.4 to 18.7. This campaign employs fake Apple ID login pages to steal sensitive user credentials and data. The exploit chain was initially disclosed by the Google Threat Intelligence Group and has since been linked to a fast-moving server cluster. Millions of iPhone users are at risk as the attack vector allows for seamless device compromise. The infrastructure reportedly spans 180 web properties and 27 hosts, indicating a broad scope of impact. Security experts are urging immediate action to mitigate the risks associated with this exploit kit.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track DarkSword in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Iranian State Actors Deploy CHOSEN BRICK Spyware Against Dissidents On September 15, 2026, the UK, US, and Netherlands issued a joint advisory regarding a spyware campaign attributed to Iranian state actors targeting dissidents, activists, and journalists. The malware, known as CHOSEN BRICK, is delivered through spear-phishing attacks on messaging platforms like WhatsApp and Telegram.…
Malicious Packagist Themes Exploit iPhones for Spyware and Crypto Theft Thirteen malicious Composer theme packages on Packagist have been identified, targeting unpatched iPhones by injecting JavaScript into Vietnamese movie and comic streaming sites. The injected code facilitates mobile ad fraud and gambling redirects, while also deploying a WebKit-to-kernel exploit chain that installs…