Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
DarkSword iOS Exploit Targets iPhone Users Worldwide

DarkSword iOS Exploit Targets iPhone Users Worldwide

Posted on March 18, 2026 By CWS

DarkSword iOS Exploit Unveiled

A sophisticated iOS exploit kit known as DarkSword has been actively used by various commercial surveillance entities and state-backed threat groups since November 2025. This exploit aims to extract sensitive personal information from iPhone users across several countries.

DarkSword utilizes a complex chain of six vulnerabilities, including four previously unknown zero-days, compromising iPhones operating on iOS versions 18.4 to 18.7.

Mechanism of the Exploit

The DarkSword exploit operates fully via JavaScript, allowing hackers to bypass Apple’s security measures such as the Page Protection Layer and Secure Page Table Monitor. This method permits the execution of unauthorized code.

Organizations like GTIG, iVerify, and Lookout have analyzed the exploit’s toolmarks, confirming its deployment in targeted attacks in Saudi Arabia, Turkey, Malaysia, and Ukraine.

Details of the Exploit Chain

The six-vulnerability chain starts with a remote code execution exploit affecting JavaScriptCore, Apple’s JavaScript engine in Safari and WebKit. It then proceeds through two sandbox escapes and a privilege escalation to execute a payload that grants hackers complete control over the device.

Among these vulnerabilities, CVE-2026-20700 involves a PAC bypass in Apple’s dynamic linker dyld, which wasn’t patched until iOS 26.3 after being reported by GTIG.

Post-Exploitation Malware Families

Following a successful DarkSword attack, three distinct malware families have been identified: GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE. Each is designed for specific threat actor objectives.

GHOSTKNIFE, used by the threat group UNC6748 through a fake Snapchat site, serves as a JavaScript backdoor for extracting account information, messages, and other data. It uses encrypted communication to avoid detection.

GHOSTSABER, deployed by the Turkish firm PARS Defense, can execute over 15 commands, including data extraction and real-time geolocation, although some features require additional modules.

GHOSTBLADE, linked to Russian espionage actor UNC6353, focuses on comprehensive data mining, gathering extensive information without persistent operation. Its code hints at future capabilities with an unimplemented function named startSandworm().

UNC6748 used a disguised Snapchat site with obfuscated JavaScript loaders to deploy DarkSword, while PARS Defense enhanced security by encrypting exploit stages.

In conclusion, the DarkSword iOS exploit poses a significant threat to iPhone security, emphasizing the need for users to remain vigilant and for developers to address such vulnerabilities promptly.

Cyber Security News Tags:Apple vulnerabilities, cyber espionage, cybersecurity threats, DarkSword exploit, iOS security, iPhone hacking, JavaScript exploits, mobile security, state-sponsored attacks, zero-day vulnerabilities

Post navigation

Previous Post: XBOW Secures $120M to Enhance AI Security Platform
Next Post: EU Imposes Sanctions on Firms Linked to Cyber Attacks

Related Posts

Spirals Ransomware Quickly Hits IT Firm with Web Shell Spirals Ransomware Quickly Hits IT Firm with Web Shell Cyber Security News
Phishing Campaign Exploits AnyDesk for Espionage Phishing Campaign Exploits AnyDesk for Espionage Cyber Security News
Users Report Teams and Access Issues Users Report Teams and Access Issues Cyber Security News
Critical jsPDF Flaw Puts Developers at Risk of Attacks Critical jsPDF Flaw Puts Developers at Risk of Attacks Cyber Security News
Hackers Delivering Cobalt Strike Beacon Leveraging GitHub and Social Media Hackers Delivering Cobalt Strike Beacon Leveraging GitHub and Social Media Cyber Security News
Writable File in Lenovo’s Windows Directory Enables a Stealthy AppLocker Bypass Writable File in Lenovo’s Windows Directory Enables a Stealthy AppLocker Bypass Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark