Google Discovers iOS Vulnerability Chain DarkSword That Can Steal Cryptocurrency Wallet Data

robot
Abstract generation in progress

Deep Tide TechFlow News, March 20 — According to Google Threat Intelligence Group (GTIG), Google’s threat intelligence team has discovered a full exploit chain called DarkSword for iOS, utilizing six vulnerabilities (including multiple zero-day exploits) to achieve complete device control. Since November 2025, it has been used by several commercial surveillance vendors and suspected state-backed threat actors to target users in Saudi Arabia, Turkey, Malaysia, and Ukraine.

DarkSword supports iOS versions 18.4 to 18.7. Upon successful intrusion, attackers can deploy three types of malware: GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER, all written in JavaScript. These malware can steal communication records, location history, browser data, and cryptocurrency wallet data, as well as record audio, take screenshots, and execute backdoor commands.

GTIG reported the vulnerabilities to Apple by the end of 2025, and all have been patched in iOS 26.3. The related domains have been added to Google’s Safe Browsing protection list. Users are advised to immediately update to the latest version of iOS.

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments