Major iPhone Security Threat "DarkSword" Puts Millions at Risk

A sophisticated new hacking technique dubbed "DarkSword" has been detailed by cybersecurity experts, potentially endangering a significant portion of iPhone users. This "fileless" exploit, which targets specific versions of iOS 18, could compromise sensitive data on millions of devices simply by visiting an infected web page.


Understanding the DarkSword Exploit

DarkSword is a "fileless" hack that takes advantage of multiple vulnerabilities when an iPhone accesses a malicious website. Unlike traditional spyware that installs persistent software, DarkSword operates by hijacking legitimate processes within the iPhone's operating system to steal data. Its stealthy nature means it leaves no trace, deleting all evidence of its activity once data theft is complete.

The attack is initiated when an iOS device encounters a "malicious iframe" embedded on a web page. From there, it can abscond with private information, including messages, iCloud content, passwords, and is specifically designed to access cryptocurrency wallets, as reported by Lookout.

Global Reach and Troubling Origins

Reports indicate that DarkSword has been actively used in various regions, including Ukraine, Saudi Arabia, Malaysia, Turkey, and Russia. Its origins may be linked to another hacking toolkit known as Coruna, which TechCrunch suggests could have been developed for the US government by the company Trenchant.

The tool reportedly became widely accessible after its Russian users inadvertently left DarkSword's source code on a public website. This leak included explanatory comments in English detailing each component, alongside the explicit "DarkSword" name for the tool, according to Wired.

Apple's Response and Urgent Call to Update

Apple has addressed the exploits utilized by both DarkSword and Coruna in recent updates to iOS 26, the company's yearly software release from 2025. However, a significant number of users remain vulnerable.

DarkSword specifically targets iOS 18 releases between iOS 18.4 and iOS 18.6.2. Apple's latest usage statistics indicate that approximately 24 percent of iOS devices are still running on iOS 18, leaving potentially hundreds of millions of iPhones exposed to this threat. Users are strongly advised to update their iOS devices to the latest available software version immediately to ensure their security.

Olley News Insight: The "fileless" nature of DarkSword underscores a growing trend in sophisticated cyberattacks, where malicious software avoids installation on the device's file system, making detection and forensic analysis much harder. This type of threat highlights the critical importance of keeping operating systems updated, as timely patches are often the only defense against such advanced exploits.

Key Takeaways

  • "DarkSword" is a new, sophisticated "fileless" hacking technique targeting iPhones.
  • It exploits vulnerabilities in iOS 18 versions (18.4 to 18.6.2).
  • The hack can steal sensitive data, including messages, iCloud content, passwords, and cryptocurrency wallet information.
  • DarkSword operates by hijacking legitimate system processes and leaves no trace after completing its data theft.
  • Reported usage locations include Ukraine, Saudi Arabia, Malaysia, Turkey, and Russia.
  • The exploit's source code became publicly available after being left on a website by Russian users.
  • Apple patched the underlying exploits in iOS 26.
  • Roughly 24% of iOS devices are still on iOS 18, making millions of users vulnerable.
  • All iPhone users capable of updating should do so immediately to the latest iOS version.