🚨 Major iOS Security Alert: "DarkSword" Zero-Day Exploit Targets Crypto Wallets
Google Threat Intelligence has identified a sophisticated new cyber-attack campaign named "DarkSword." This threat utilizes a chain of six zero-day vulnerabilities to fully compromise iPhones, specifically those running iOS 18.4 through 18.7.
The exploit is extremely dangerous because it requires no user interaction or app installation. Simply visiting a compromised or "watering hole" website via Safari can allow attackers to gain kernel-level access and take total control of your device.
Who is at risk?
DarkSword is engineered to hunt for and drain high-value targets. It specifically scans for and compromises the following:
Exchange & Wallet Apps: Coinbase, Binance, Kraken, KuCoin, OKX, MEXC, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe.
Hardware Wallet Interfaces: Critical data from Ledger and Trezor companion apps.
How it works:
The "Hit-and-Run": The malware is designed for rapid exfiltration. It steals private keys, passwords, and sensitive account data within minutes.
Invisible Cleanup: Once the data is stolen, DarkSword automatically wipes its own traces to avoid forensic detection, making it nearly impossible to notice after a reboot.
The Culprits: The activity is linked to the Russian-backed group UNC6353 and Turkish vendor PARS Defense. Victims have already been identified across Ukraine, Saudi Arabia, Turkey, and Malaysia.
🛡️ Urgent Action Required:
All vulnerabilities used in this attack have been patched in iOS 26.3.1. If you are still running an older version of iOS 18, your assets are considered at high risk.
Security Recommendations:
Update Immediately: Move to iOS 26.3.1 or the latest available version.
Lockdown Mode: If you cannot update immediately, enable "Lockdown Mode" in your iPhone settings to block these advanced web-based exploits.
#DarkSword #iOSSecurity #CryptoSafety #CyberAttack #iPhoneUpdate $BNB $UNI