Back to Intel

Intel Node

The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors

lowvulnerability2026-03-18T14:00:00+00:00source excerpt
aptmalwarevulnerabilityexploitationcloud

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Introduction Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors utilizing DarkSword in distinct campaigns. These threat actors have deployed the exploit chain against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine. DarkSword supports iOS versions 18. 4 through 18.

7 and utilizes six different vulnerabilities to deploy final-stage payloads. GTIG has identified three distinct malware families deployed following a successful DarkSword compromise: GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER.

Read Original Source