DarkSword iPhone attacks steal credentials and files

Published August 4, 2026

DarkSword uses fake Apple login pages to compromise vulnerable iPhones. It can steal credentials and files without another tap.

Report priority
High
Targets
Safari

How it works

  • An attacker sends someone to a malicious page that resembles an Apple login.
  • The page secretly loads code chosen for the iPhone's iOS version.
  • That code combines six flaws to escape Safari's protections and install GHOSTBLADE.
  • The implant copies keychain, iCloud, and Wi-Fi credentials.
  • It also sends files to servers controlled by the operator.

What to do

Check the iOS version installed on the iPhone. The reported chain targets iOS 18.4 through 18.7. Having one of these versions shows exposure, not proof of compromise.

Ask Apple or your device administrator which current release addresses this chain. Avoid entering an Apple ID through unexpected links.

Technical details

Affected software: Safari

Researchers observed at least seven operators using the leaked DarkSword code on live infrastructure. One Chinese-speaking operator controlled over 100 web properties, including a fake Apple login page hosted alongside DarkSword.

DarkSword is a leaked JavaScript exploit chain combining six iOS flaws across Safari and deeper system components. It gains extensive system access, escapes the browser's restrictions, and installs GHOSTBLADE. Researchers linked identical core files to many active properties. Operators changed loaders for different iOS versions while reusing the credential and file-stealing modules.