DarkSword iOS Exploit Targets Crypto Wallets as Mobile Attacks Turn Financially Motivated
High-end iOS exploits were once used mainly for government surveillance and intelligence gathering. Smartphones now hold identity credentials, communications and crypto assets, making them a direct avenue for monetization. Google's Threat Intelligence Group (GTIG), Lookout and iVerify said DarkSword can silently compromise an iPhone when a user visits a hacked website, stealing private keys, wallets and login credentials. The campaign underscores a shift in attackers' motives toward financial crime.
GTIG, Lookout and iVerify disclosed DarkSword on March 18–19, 2026. The attacks date to November 2025, targeted four countries and chained six vulnerabilities affecting iOS 18.4 through 18.7. Apple fixed all the flaws in iOS 26.3 and released iOS/iPadOS 18.7.7 on March 24 to protect older devices. No victim count or value of stolen assets has been disclosed to date.
All Coverage
7 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.