DarkSword iOS Exploit Chain Targets Users Through Compromised Ukrainian Websites

Summary
Lookout researchers detail DarkSword, an iOS exploit chain used through compromised Ukrainian websites to steal personal data and cryptocurrency-related information from targeted iPhones, then quickly erase its files and exit.
Key points
- DarkSword targets iPhones running iOS versions 18.4 through 18.6.2, using malicious iframes on compromised Ukrainian websites to deliver the exploit chain.
- The JavaScript chain escapes Safari’s WebContent sandbox, gains kernel read/write access, and injects payloads into privileged iOS services.
- It steals data including messages, emails, photos, credentials, location history, iCloud files, and cryptocurrency wallet information, then removes staged files and exits within minutes.
- Lookout attributes the activity to UNC6353, an unknown actor assessed as likely Russian-linked; the group has also deployed the Coruna iOS exploit chain.
- Researchers observed targeting through compromised Ukrainian news and government websites, and potential infection of an employee at a Ukrainian food-processing manufacturer.
- Lookout says devices updated to iOS 18.7.3 or later, or iOS 26.3 or later, are not susceptible; it recommends keeping mobile operating systems up to date.
Article Details
- Attack Vectors
- UNC6353 used compromised Ukrainian websites as watering holes, injecting iframes that loaded JavaScript from static.cdncounter[.]net.
- The loader fingerprinted visiting devices and routed selected iOS versions to the DarkSword exploit chain.
- DarkSword exploited Safari's WebContent sandbox, used WebGPU to inject into mediaplaybackd, and gained kernel read/write access to reach privileged processes and restricted files.
- Post-exploitation payloads collected sensitive data, including credentials, messages, photos, and cryptocurrency-wallet information, and sent it to a C2 server before deleting staged files.
- Defensive Notes
- According to Lookout, devices running iOS 18.7.3 or later in the iOS 18 line, or iOS 26.3 or later in the iOS 26 line, are not susceptible to the reported threat or its exploited vulnerabilities.
- Lookout recommends identifying out-of-date devices and updating mobile devices promptly; organizations should replace older iOS device models where necessary.
- Lookout says its Safe Browsing and Device Compromise Detection features protect customers, while its Web History feed can help identify exposed or compromised devices.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | cdncounter[.]net | Domain associated with UNC6353's DarkSword exploit-delivery infrastructure. |
| DOMAIN | uacounter[.]com | Domain Lookout identifies as infrastructure tied to UNC6353's earlier Coruna activity. |
| HOSTNAME | 7aac[.]gov[.]ua | Compromised Ukrainian government website observed with malicious iframes linked to DarkSword and, previously, Coruna delivery infrastructure. |
| HOSTNAME | cdn[.]cdncounter[.]net | Host listed in the article's network IoCs for the DarkSword threat. |
| HOSTNAME | cdn[.]uacounter[.]com | Domain Google tied to UNC6353; a compromised Ukrainian site previously used an iframe linked to it to deliver Coruna. |
| HOSTNAME | count[.]cdncounter[.]net | Host listed in the article's network IoCs for the DarkSword threat. |
| HOSTNAME | novosti[.]dn[.]ua | Compromised Ukrainian news website observed with a malicious iframe linked to DarkSword delivery infrastructure. |
| HOSTNAME | sqwas[.]shapelie[.]com | DarkSword C2 subdomain apparently created by the threat actor on a compromised Ukrainian domain. |
| HOSTNAME | static[.]cdncounter[.]net | DarkSword exploit-delivery host loaded by malicious iframes on compromised websites. |
| IPV4 | 141[.]105[.]130[.]237 | IP address listed in the article's DarkSword network IoCs, with dates 2025-12-22 to 2026-03-17. |
MITRE ATT&CK
T1005 · Data from Local SystemDarkSword collected information from the device, including photos, notes, messages, saved passwords, and cryptocurrency-wallet data.T1041 · Exfiltration Over C2 ChannelDarkSword sent collected device data to its hardcoded C2 server.T1055 · Process InjectionDarkSword injected into mediaplaybackd and later injected an exfiltration payload into Springboard.T1068 · Exploitation for Privilege EscalationDarkSword obtained kernel read/write access and modified sandbox restrictions to access privileged processes and restricted files.T1070.004 · File DeletionAfter exfiltration, DarkSword deleted the files it had created on the device.T1074.001 · Local Data StagingPayloads staged collected passwords, keys, and documents in accessible locations before exfiltration.T1189 · Drive-by CompromiseCompromised Ukrainian websites served malicious iframes to visitors, initiating the iOS exploit chain.T1203 · Exploitation for Client ExecutionDarkSword exploited vulnerabilities after Safari loaded the malicious iframe to execute its iOS payload.T1539 · Steal Web Session CookieSafari cookies were among the data DarkSword collected.
Threat Actors
APT29Group cited in a separate 2024 campaign involving watering holes on compromised Mongolian websites and iOS and Android exploits.Sandworm APTGroup cited for targeting cryptocurrencies with Infamous Chisel tooling against Ukrainian armed forces' Android devices.TrickBotCybercrime gang mentioned in connection with the exploit broker Matrix LLC / Operation Zero; no role in DarkSword is reported.UNC6353Google's designation for the unknown, likely Russian actor that Lookout reports deployed DarkSword and Coruna through watering holes on compromised Ukrainian websites.UNC6691Chinese criminal group reported by Google to have used Coruna; the article does not link it to DarkSword deployment.
Malware
Corunaby the same unknown, likely Russian, threat actor (dubbed UNC6353 by Google) who also deployed the Coruna exploit chain reported earlier this year, which was reported by Google and iVerify. As was the case forDarkSwordIn a tangible example of how attacks are evolving, Lookout Threat Labs has discovered DarkSword, a full iOS exploit chain and payload for iPhones running iOS versions between iOS 18.4 and 18.6.2. This threat wasInfamous Chiselthat has been observed for other Russian APTs. Also, Sandworm APT targeted cryptocurrencies in their Infamous Chisel tooling which targeted Ukrainian armed forces’ Android devices.
Vendors
Products
iOSIn a tangible example of how attacks are evolving, Lookout Threat Labs has discovered DarkSword, a full iOS exploit chain and payload for iPhones running iOS versions between iOS 18.4 and 18.6.2. This threat wasiPhonesare evolving, Lookout Threat Labs has discovered DarkSword, a full iOS exploit chain and payload for iPhones running iOS versions between iOS 18.4 and 18.6.2. This threat was deployed by the same unknown, likelySafariexecution to access sensitive information and exfiltrate it off the device. The kill chain begins with Safari encountering the malicious iframe embedded in a web page. Once loaded, Darksword breaks out of the
Countries
ChinaMongoliaRussiaThere are some noteworthy overlaps between certain characteristics of this campaign and previous Russia-linked activity. In 2024, Google published research on a campaign conducted by APT29 using watering hole attacks onUkraineDonbas which provides information on the frontline situation and social issues in the Donbas region of Ukraine. The 7aac.gov[.]ua site is an official website for the Seventh Administrative Court of Appeals, which
Industries
Cryptocurrencya final exfiltration payload is injected into Springboard where the staged data along with emails, cryptocurrency wallets, usernames, passwords, photos, and other files are lifted from the device is then sent to aFood processingVinnytsia. Lookout researchers have observed evidence of a potential infection of an employee at a food processing manufacturer in Ukraine on February 12th, 2026.GovernmentA malicious iframe discovered on the compromised Ukrainian government website 7aac.gov[.]ua.While it initially appeared that this may be another site distributing Coruna, upon closer inspection of the our researchersNews media