DarkSword iPhone attacks steal credentials and files
DarkSword uses fake Apple login pages to compromise vulnerable iPhones. It can steal credentials and files without another tap.
- Report priority
- High
- Targets
- Safari
How it works
- An attacker sends someone to a malicious page that resembles an Apple login.
- The page secretly loads code chosen for the iPhone's iOS version.
- That code combines six flaws to escape Safari's protections and install GHOSTBLADE.
- The implant copies keychain, iCloud, and Wi-Fi credentials.
- It also sends files to servers controlled by the operator.
What to do
Check the iOS version installed on the iPhone. The reported chain targets iOS 18.4 through 18.7. Having one of these versions shows exposure, not proof of compromise.
Ask Apple or your device administrator which current release addresses this chain. Avoid entering an Apple ID through unexpected links.
Technical details
Affected software: Safari
Researchers observed at least seven operators using the leaked DarkSword code on live infrastructure. One Chinese-speaking operator controlled over 100 web properties, including a fake Apple login page hosted alongside DarkSword.
DarkSword is a leaked JavaScript exploit chain combining six iOS flaws across Safari and deeper system components. It gains extensive system access, escapes the browser's restrictions, and installs GHOSTBLADE. Researchers linked identical core files to many active properties. Operators changed loaders for different iOS versions while reusing the credential and file-stealing modules.