iPhone Security Alert: Darksword Spyware Targets Millions via Ukraine Websites
Sophisticated 'Darksword' spyware targets iPhones through compromised Ukrainian websites, researchers warn.

Top Summary
- What happened: 'Darksword' spyware was found on Ukrainian websites, exploiting vulnerabilities in older iPhone iOS versions.
- Why it matters: This marks the second major iPhone spyware discovery this month, indicating a growing market for sophisticated mobile malware.
- What changes for people: Users with outdated iOS versions (18.4 to 18.6.2) are at risk. Updating to the latest iOS is crucial.
- Who is affected: Potentially 220 to 270 million iPhone users who haven't updated their iOS. Targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.
Darksword: A New iPhone Threat
Researchers have uncovered a powerful spyware exploit dubbed 'Darksword' targeting Apple iPhones. It was found planted on dozens of websites in Ukraine.
This discovery, along with the recent 'Coruna' spyware reveal, highlights the increasing availability of advanced hacking tools. These tools are capable of stealing sensitive data and cryptocurrency wallet information.
The Technical Details
Cybersecurity firms Lookout, iVerify, and Google's researchers coordinated analyses of the Darksword malware. They found it hosted on the same servers as the previously discovered 'Coruna' spyware.
According to researchers, Darksword targets iPhone users running iOS versions 18.4 to 18.6.2. These versions were released by Apple between March and August 2025.
It's unclear exactly how many iPhones are vulnerable. However, estimates suggest a significant number remain unpatched.
Who's Behind the Attacks?
Google's researchers observed multiple commercial vendors and suspected state-linked hackers using Darksword. These attacks targeted users in Saudi Arabia, Turkey, Malaysia, and Ukraine.
The campaigns in Malaysia and Turkey are linked to Turkish commercial surveillance vendor PARS Defense. PARS Defense did not respond to requests for comment.
Apple's Response
An Apple spokesperson stated that the exploits targeted "out-of-date software." They emphasized that the underlying vulnerabilities have been addressed through multiple updates.
"Keeping software up to date remains the single most important thing users can do to maintain the high security of their Apple devices,"
the spokesperson said.
Apple also confirmed that all malicious domains identified by Google are blocked by Apple Safe Browsing in Safari.
The Rise of Commercial Spyware
The discovery of two distinct iOS exploits this month suggests a thriving ecosystem for these tools. Previously, such sophisticated malware was primarily limited to state-level intelligence operations.
Rocky Cole, co-founder and COO of iVerify, noted the sloppy security mistakes associated with Darksword. This suggests the attackers are less concerned about detection.
"The fact that they don’t care if it gets burned, and that they’re using them in mass attacks with poor (operational security), that says a lot about how much they value these tools,"
Cole said.
What to Watch Next
The cybersecurity community will be closely monitoring the evolution of Darksword and Coruna. Investigations into the actors behind these campaigns and the potential for further attacks are ongoing. Users should prioritize updating their devices immediately.
