DarkSword iOS exploit kit spreads via fake iPhone Duo preorder scam and Ukraine watering holes
The DarkSword Safari exploit chain is hitting iPhones both through a fake iPhone Duo preorder page and watering-hole attacks on compromised news and government sites, with Ukrainian officials warning Russian-aligned hackers are using it and other tools for…
Malwarebytes discovered a fake Apple iPhone Duo preorder page that launches the DarkSword exploit chain in Safari as soon as the page opens, with the preorder form acting only as a decoy. The follow-on payload attempts to steal keychain credentials, cryptocurrency wallet files, Apple Notes, messages, contacts, photos, and cached location data, then polls a server for commands; the chain matches vulnerabilities Google described in March and has been patched by Apple, with iOS 18.4 through 18.6.2 previously the targeted range. Separately, Ukraine's SSSCIP warned that Russian-aligned hackers are targeting iPhones and Android phones used by military personnel and government officials, saying DarkSword has been deployed in watering-hole attacks on compromised news and government sites that steal data within minutes and then remove themselves. Lookout attributes related DarkSword activity in Ukraine to UNC6353, and groups UAC-0244 and UAC-0263 distributed the CamelSpy and BTMOB malware families through decoy websites. The two accounts differ in emphasis: Malwarebytes researchers analyzed captured code but did not observe data leaving a real compromised iPhone, while SSSCIP describes rapid data theft and self-removal on infected devices.
- A fake Apple iPhone Duo preorder page launches the DarkSword exploit chain in Safari on page open; the form is a decoy and no submission is needed (Malwarebytes, 2026-09-29).
- DarkSword's payload targets keychain credentials, cryptocurrency wallet files, Apple Notes, messages, contacts, photos, and cached location data, then polls a server for commands.
- The chain matches vulnerabilities Google described in March; Apple has patched them, and iOS 18.4 through 18.6.2 were previously the targeted builds.
- Malwarebytes analysts did not confirm data actually leaving a real compromised iPhone.
- Ukraine's SSSCIP says DarkSword is used in watering-hole attacks on compromised news and government sites, stealing data within minutes and then removing itself (The Record, 2026-09-30).
- SSSCIP attributes the targeting to Russian-aligned hackers seeking espionage and theft against military personnel and government officials, on both iOS and Android devices.
- Lookout attributes earlier DarkSword activity in Ukraine to UNC6353.
- Group UAC-0244 distributes CamelSpy and group UAC-0263 distributes BTMOB through decoy websites.
Coverage timelineoldest first · each row is one article
- · 1d agoFake iPhone Duo preorder scam triggers DarkSword attack
Malwarebytes Labs· 74
A fake iPhone Duo preorder page uses the patched DarkSword chain to steal iPhone data on visit.
- · 14h agoMobile malware warning from Ukrainian researchers includes iPhone exploit kit
The Record· 76
Ukraine warns Russian-aligned hackers are infecting military and officials' iPhones and Android phones for espionage.