Rare iPhone Spyware DarkSword Exploits One Website Visit
New iPhone spyware DarkSword Discovered
A newly documented iPhone spyware tool, DarkSword, can compromise a device simply through a visit to a hacked website, researchers say. Google Threat Intelligence Group (GTIG), in partnership with Lookout and iVerify, identified a full-chain iOS exploit that relies on several zero-day vulnerabilities to break into Safari, escape its sandbox, gain deeper access to iOS, steal data, and remove itself within minutes. The toolkit is described as targeting iPhones running specific versions of iOS 18, with patches from Apple noted by researchers.
The attack is described as a watering hole campaign, where attackers compromised websites their targets were likely to visit and used those sites to deliver the exploit. GTIG said a suspected Russian espionage group, UNC6353, used DarkSword in watering hole attacks on Ukrainian websites, while TechCrunch reported that the malware was designed to infect anyone who visited certain Ukrainian sites from within the country.
Technical Details and Campaign Context
In this case, the attack starts in JavaScriptCore, the engine used by Safari and WebKit to run website code. From there, the attackers break out of Safari's sandbox, infect the GPU process, then move into a more privileged iOS system service called mediaplaybackd. Finally, the chain uses kernel flaws to raise privileges and deploy the spyware payload. Google said the chain used multiple vulnerabilities across Apple's software stack, including memory corruption bugs in JavaScriptCore, a flaw in ANGLE used by Safari's graphics handling, and kernel issues in XNU, the core of iOS. Some of those flaws were exploited as zero-days, meaning attackers used them before fixes were publicly available. The researchers say the relevant fixes were shipped by Apple across iOS 18.6, 18.7.2, 18.7.3, 26.1, 26.2, and 26.3, depending on the bug.
The attack is described as a full-chain exploit, linking several bugs to move from a web page to full control of the phone. GTIG said the hacker group behind the spyware has deployed the exploit chain in Saudi Arabia, Turkey, and Malaysia. The publication notes that DarkSword was built to steal passwords, photos, browser history, and messages from apps, including WhatsApp and Telegram, along with SMS texts. Researchers also found code aimed at cryptocurrency wallet apps; however, it cannot be said for sure that the main objective behind spreading the spyware was financial gain. Unlike spyware designed for long-term surveillance, the researchers described DarkSword as operating in a quick, short dwell time, likely minutes, before data is sent away and the intruder disappears. GTIG also shared code snippets showing efforts to delete crash logs to make the intrusion harder to spot.
Apple is said to have patched the vulnerabilities in later updates, with fixes rolled out across several iOS versions. The total number of infected devices remains difficult to gauge, according to the researchers.
Key Technical Aspects
- Initial vector: JavaScriptCore inside Safari/WebKit
- Sandbox escape sequence, moving from Safari to GPU process, then mediaplaybackd
- Privilege escalation: kernel-level flaws in XNU
- Exploited bugs: memory corruption in JavaScriptCore, ANGLE graphics flaw, kernel vulnerabilities
- Exploits were zero-day in some cases
- Targets: iPhones running specific versions of iOS 18
- Patch timeline: fixes shipped across iOS 18.6, 18.7.2, 18.7.3, 26.1, 26.2, 26.3
- Campaign type: watering hole, targeting Ukrainian websites; activity linked to UNC6353
- Likely data exfiltration: passwords, photos, browser history, messages from apps (WhatsApp, Telegram), and SMS
- Code indicators: signs of crash log deletion to aid covertness
The report underscores that the overall scale of impact is hard to measure, given the covert nature of the activity and the short dwell times described by GTIG. While the patching of vulnerabilities reduces risk for many devices, the attack chain demonstrates how a single website visit can trigger a multi-stage breach on a target device. The collaboration among GTIG, Lookout, and iVerify reflects ongoing intelligence-sharing efforts to map and expose advanced iOS threat campaigns.
Authorities and security researchers continue to monitor for any broader deployment of the DarkSword tool and any updates to the exploit chain. The interplay of watering hole tactics, zero-day vulnerabilities, and rapid data exfiltration illustrates the persistent risk landscape for iPhone users, even on devices kept up to date with the latest official patches.