CVE Tools

The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors

MandiantBy Google Threat Intelligence Group25 min read

Reported exploitediOSUNC6748
Read at Mandiant

Below is the opening; the full story is at Mandiant.

From Mandiant

Introduction

Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors utilizing DarkSword in distinct campaigns. These threat actors have deployed the exploit chain against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.…

Continue at Mandiant

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store