DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors (CVE-2026-20700, CVE-2025-43529, CVE-2025-31277) — Threadlinqs Intelligence
As of 2026-05-30, DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors (CVE-2026-20700, CVE-2025-43529, CVE-2025-31277) is a critical-severity zero day threat attributed to UNC6353 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-0245 · Severity: CRITICAL · CVSS: 9.8 · Status: MONITORING · Category: ZERO_DAY
Attribution: UNC6353 · Russia · ESPIONAGE
GTIG reports the proliferation of DarkSword, a full iOS exploit chain leveraging six zero-day vulnerabilities now adopted by Russian espionage group UNC6353, Saudi-targeting cluster UNC6748, and
DarkSword is a sophisticated, full iOS exploit chain and infostealer platform that represents a new phase in mobile threats where advanced exploit capabilities originally developed for nation-state espionage are being commoditized and adopted by multiple distinct threat actors for both surveillance and financial gain.
The exploit chain targets iPhones running iOS versions 18.4 through 18.7 using a multi-stage attack architecture. For devices running iOS prior to 18.6, DarkSword exploits CVE-2025-31277, a JIT optimization type confusion bug in JavaScriptCore. For devices running iOS 18.6-18.7, it leverages CVE-2025-43529, a use-after-free vulnerability in the Data Flow Graph (DFG) JIT layer of JavaScriptCore. Both WebKit vulnerabilities are chained with CVE-2026-20700, a memory corruption bug in dyld (Dynamic Link Editor) used as a user-mode Pointer Authentication Codes (PAC) bypass to achieve arbitrary code execution. Additional vulnerabilities in the chain include CVE-2025-14174 (out-of-bounds memory access in ANGLE), CVE-2025-43510, and CVE-2025-43520.
The attack chain follows a precise sequence: (1) Initial access via watering hole — malicious iframe or script tag injected into compromised legitimate websites loads rce_loader.js from attacker infrastructure; (2) Device fingerprinting — JavaScript identifies the target iOS version and routes to the appropriate exploit module (rce_worker_18.4.js or rce_worker_18.6.js); (3) WebKit exploitation — triggers the appropriate JIT vulnerability for remote code execution; (4) PAC bypass — chains CVE-2026-20700 in dyld to bypass Pointer Authentication Codes; (5) Sandbox escape — uses WebGPU as a pivot point, injecting into mediaplaybackd to break the WebContent sandbox; (6) Privilege escalation — achieves kernel read/write access; (7) Post-exploitation — pe_main.js injects payloads into privileged iOS services including configd, wifid, securityd, UserEventAgent, and Springboard.
Three distinct malware families are deployed as final payloads: GHOSTBLADE, a JavaScript dataminer that collects and exfiltrates data over HTTP(S) without persistence or backdoor functionality; GHOSTKNIFE, details of which remain limited; and GHOSTSABER, a JavaScript backdoor with C2 communication, device enumeration, file listing, data exfiltration, and arbitrary JavaScript execution capabilities.
DarkSword employs a hit-and-run operational pattern with a dwell time measured in minutes. Data exfiltration targets include: device identifiers, SMS/iMessage, call history, address book, WiFi credentials, Safari history and cookies, location data, photos, calendar, health data, notes, emails, installed applications, saved passwords, and messaging platform data from Telegram and WhatsApp. A significant focus on cryptocurrency theft targets exchanges including Coinbase, Binance, Kraken, Kucoin, Okx, and Mexc, as well as wallets including Ledger, Trezor, Metamask, Exodus, Uniswap, Phantom, and Gnosis Safe. After exfiltration, the malware performs filesystem cleanup and process termination to minimize forensic evidence.
GTIG has attributed DarkSword usage to three distinct threat clusters: UNC6353, a Russian-backed espionage group conducting watering hole campaigns against Ukrainian users by compromising Ukrainian government and media websites; UNC6748, which targeted Saudi Arabian users via a Snapchat-themed lure site (snapshare.chat) beginning in early November 2025; and PARS Defense, a Turkish commercial surveillance vendor that deployed DarkSword with improved OPSEC including code obfuscation and ECDH/AES encryption in Turkey (November 2025) and Malaysia (January 2026). The UNC6353 campaign is notable for poor operational security including zero obfuscation of JavaScript/HTML, a server component labeled Dark Sword File Receiver, and evidence of LLM-generated code with detailed comments.
The DarkSword campaign is connected to the Coruna iOS exploit kit, which shares command-and-control infrastructure but is operated
Weaknesses (CWE)
CWE-416, CWE-843, CWE-787, CWE-119
Target sectors: government, financial, defense, media, judiciary, cryptocurrency, telecommunications, civil-society
Target regions: Ukraine, Saudi Arabia, Turkey, Malaysia, Eastern Europe, Middle East, Southeast Asia
Detections & IOCs
As of 2026-07-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
ZERO_DAY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-20700, CVE-2025-43529, CVE-2025-31277, CVE-2025-14174, CVE-2025-43510, CVE-2025-43520, T1189, T1583, T1584, T1587, T1588, T1203, T1059, T1068, T1055, T1211