DarkSword iOS Malware Exploit Chain Targets Multiple Nations
Patch iOS devices to the latest version (18.8 or later) to mitigate DarkSword exploitation.
Patch iOS devices to the latest version (18.8 or later) immediately to mitigate DarkSword exploitation.
Summary
Google Threat Intelligence Group (GTIG) uncovered DarkSword, a sophisticated iOS exploit chain that leverages six zero‑day vulnerabilities to fully compromise devices running iOS 18.4 through 18.7. The chain, identified in November 2025, has been used by commercial surveillance vendors and suspected state‑sponsored actors against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine. After a successful compromise, three distinct malware families—GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER—are deployed. UNC6353, a Russian espionage group, has recently incorporated DarkSword into watering‑hole campaigns. A leaked version of the exploit appeared on the internet a week after discovery, broadening its reach.
The threat underscores the importance of timely iOS updates; devices remain safe if patched regularly.
Key changes
- DarkSword targets iOS 18.4‑18.7 using six zero‑day vulnerabilities
- Three malware families—GHOSTBLADE, GHOSTKNIFE, GHOSTSABER—are deployed after compromise
- The chain has been used by state‑sponsored actors in Saudi Arabia, Turkey, Malaysia, and Ukraine
- UNC6353, a Russian espionage group, incorporated DarkSword into watering‑hole campaigns
- A leaked version appeared on the internet a week after discovery, expanding its reach
- DarkSword was identified by Google Threat Intelligence Group in November 2025
- The chain is named DarkSword after recovered payload toolmarks