Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. (google.com) DarkSword iOS Full-Chain Exploit Adopted by Multiple Threat Actors Across Distinct Campaigns

(google.com) DarkSword iOS Full-Chain Exploit Adopted by Multiple Threat Actors Across Distinct Campaigns

Scheduled Pinned Locked Moved Uncategorized
threatintelcybersecurity
1 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.comO This user is from outside of this forum
    orlysec@swecyb.com
    wrote last edited by
    #1

    (google.com) DarkSword iOS Full-Chain Exploit Adopted by Multiple Threat Actors Across Distinct Campaigns

    Google Threat Intelligence Group has identified DarkSword, a full chain iOS exploit kit leveraging six zero day vulnerabilities across iOS 18.4 through 18.7, deployed by three threat actors including UNC6748, PARS Defense, and suspected Russian group UNC6353. Active since at least November 2025, campaigns targeted users in Saudi Arabia, Turkey, Malaysia, and Ukraine. The chain exploits flaws in JavaScriptCore, ANGLE WebGL, XNU memory management, and XNU VFS for full kernel compromise, delivering three post exploitation malware families: GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER. All vulnerabilities have been patched by Apple.

    IOCs in the article.

    Source: https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/

    #ThreatIntel #Cybersecurity

    1 Reply Last reply
    1
    0
    • R relay@relay.infosec.exchange shared this topic
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Tags
    • Popular
    • World
    • Users
    • Groups