DarkSword iOS Exploit Chain Targets Users Through Compromised Ukrainian Websites

· Original article ↗

Summary

Lookout researchers detail DarkSword, an iOS exploit chain used through compromised Ukrainian websites to steal personal data and cryptocurrency-related information from targeted iPhones, then quickly erase its files and exit.

Key points

  • DarkSword targets iPhones running iOS versions 18.4 through 18.6.2, using malicious iframes on compromised Ukrainian websites to deliver the exploit chain.
  • The JavaScript chain escapes Safari’s WebContent sandbox, gains kernel read/write access, and injects payloads into privileged iOS services.
  • It steals data including messages, emails, photos, credentials, location history, iCloud files, and cryptocurrency wallet information, then removes staged files and exits within minutes.
  • Lookout attributes the activity to UNC6353, an unknown actor assessed as likely Russian-linked; the group has also deployed the Coruna iOS exploit chain.
  • Researchers observed targeting through compromised Ukrainian news and government websites, and potential infection of an employee at a Ukrainian food-processing manufacturer.
  • Lookout says devices updated to iOS 18.7.3 or later, or iOS 26.3 or later, are not susceptible; it recommends keeping mobile operating systems up to date.

Article Details

Attack Vectors
  • UNC6353 used compromised Ukrainian websites as watering holes, injecting iframes that loaded JavaScript from static.cdncounter[.]net.
  • The loader fingerprinted visiting devices and routed selected iOS versions to the DarkSword exploit chain.
  • DarkSword exploited Safari's WebContent sandbox, used WebGPU to inject into mediaplaybackd, and gained kernel read/write access to reach privileged processes and restricted files.
  • Post-exploitation payloads collected sensitive data, including credentials, messages, photos, and cryptocurrency-wallet information, and sent it to a C2 server before deleting staged files.
Defensive Notes
  • According to Lookout, devices running iOS 18.7.3 or later in the iOS 18 line, or iOS 26.3 or later in the iOS 26 line, are not susceptible to the reported threat or its exploited vulnerabilities.
  • Lookout recommends identifying out-of-date devices and updating mobile devices promptly; organizations should replace older iOS device models where necessary.
  • Lookout says its Safe Browsing and Device Compromise Detection features protect customers, while its Web History feed can help identify exposed or compromised devices.

Indicators of compromise

TypeIndicatorContext
DOMAINcdncounter[.]netDomain associated with UNC6353's DarkSword exploit-delivery infrastructure.
DOMAINuacounter[.]comDomain Lookout identifies as infrastructure tied to UNC6353's earlier Coruna activity.
HOSTNAME7aac[.]gov[.]uaCompromised Ukrainian government website observed with malicious iframes linked to DarkSword and, previously, Coruna delivery infrastructure.
HOSTNAMEcdn[.]cdncounter[.]netHost listed in the article's network IoCs for the DarkSword threat.
HOSTNAMEcdn[.]uacounter[.]comDomain Google tied to UNC6353; a compromised Ukrainian site previously used an iframe linked to it to deliver Coruna.
HOSTNAMEcount[.]cdncounter[.]netHost listed in the article's network IoCs for the DarkSword threat.
HOSTNAMEnovosti[.]dn[.]uaCompromised Ukrainian news website observed with a malicious iframe linked to DarkSword delivery infrastructure.
HOSTNAMEsqwas[.]shapelie[.]comDarkSword C2 subdomain apparently created by the threat actor on a compromised Ukrainian domain.
HOSTNAMEstatic[.]cdncounter[.]netDarkSword exploit-delivery host loaded by malicious iframes on compromised websites.
IPV4141[.]105[.]130[.]237IP address listed in the article's DarkSword network IoCs, with dates 2025-12-22 to 2026-03-17.

MITRE ATT&CK

Threat Actors

Malware

Vendors

Products

Countries

Industries

Related Articles