DarkSword iOS Toolkit Now Public on GitHub, Lowering Barrier for Potential iPhone Exploit

DarkSword is designed to extract sensitive data from older, unpatched smartphones.

Advertisement
Written by Shaurya Tomer, Edited by David Delima | Updated: 24 March 2026 13:42 IST
Highlights
  • The spyware is designed to steal messages, passwords, and photos
  • DarkSword has been listed on GitHub, raising exploitation concerns
  • It uses zero-day vulnerabilities to completely compromise devices

DarkSword used Safari, GPU, and kernel exploits to move from a website visit to full iPhone compromise

Photo Credit: Pexels/ Karolina Grabowska

Cybersecurity researchers recently warned of a growing threat that targeted older iPhone models. This threat, which was previously linked to targeted attacks, seems to have escalated after a more advanced version of the DarkSword hacking toolkit was leaked online. It is now available on public code-sharing platforms like GitHub, potentially making it significantly easier for threat actors to exploit vulnerabilities in older Apple devices.

DarkSword Code Published on GitHub

According to iVerify researchers, the updated version of DarkSword has been uploaded to GitHub, making it easier to access and deploy. The spyware is said to target several iPhone and iPad models running older versions of iOS, particularly iOS 18. It was still available on the platform at the time of publishing this story.

Advertisement

In a conversation with TechCrunch, Matthias Frielingsdorf, Co-Founder of iVerify, said that the updated versions of DarkSword share the same infrastructure as the original exploit. iVerify was one of the security firms that originally discovered the hacking campaign, alongside Lookout and Google Threat Intelligence Group (GTIG).

The code is said to consist of relatively basic HTML and JavaScript files, which can be hosted on a server within minutes. This potentially allows attackers to create malicious webpages designed to compromise vulnerable devices.

Advertisement

A security researcher also reportedly claimed to have successfully utilised the publicly available version of the exploit to compromise an iPad mini running iOS 18. This indicates that the attack can potentially be executed by threat actors without requiring advanced technical expertise.

Apple said it is aware of the exploit affecting devices running older and outdated operating systems. The company recently released an emergency update to address vulnerabilities on devices that cannot be upgraded to the latest iOS versions. As per the iPhone maker, devices with Lockdown Mode enabled are also protected from these specific attacks, even on out-of-date software.

Advertisement

However, the tech giant reiterated that such devices should also be updated to the latest iOS version as soon as possible.

What is DarkSword Spyware?

The DarkSword spyware is an iOS full-chain exploit that leveraged multiple zero-day (undiscovered) vulnerabilities to completely compromise devices. Now available as a toolkit on code-sharing platforms, it links together several bugs to move from a web page to full control of the phone.

Advertisement

DarkSword is designed to extract sensitive data from compromised devices, as per security researchers. It can access contacts, messages, call history, and data stored in the iOS Keychain, including passwords and other credentials, and transmit this information to attacker-controlled servers.

Researchers note that comments within the leaked source code describe the operation of the exploit in detail, including specific instructions for exfiltrating data across the internet. In certain instances, the code is said to reference post-exploitation activities, outlining the processes for collecting and remotely transmitting data once a device has been compromised.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 4b Teaser Suggests the Phone Could Launch in India Very Soon
  2. Tecno Camon Slim Launched With MediaTek Helio G200 Ultimate, 144Hz Display
  1. In a Massive Shakeup, Meta Appoints CRED’s Kunal Shah to Lead WhatsApp Globally as Will Cathcart Exits
  2. iPhone Air 2 to Arrive With Chip Downgrade and Two Rear Cameras, Tipster Claims
  3. Halo: Campaign Evolved Won't Require PS Plus for Local Split Screen Co-Op on PS5, Halo Studios Clarifies
  4. OnePlus 16T Display, Chipset Details Leaked Months Ahead of Anticipated Debut
  5. iPhone, iPad and Mac Price Hikes Could Be 'Fairly Imminent': Mark Gurman
  6. Honor X80 Pro Max Launched With '10,000-Nit' Display, 11,000mAh Battery: Price, Specifications
  7. Secret Network Bridge Suffers $4.7 Million Exploit Due to Infinite Mint Bug
  8. Mid-Range 4G Phones Tipped to Launch in India Between July and September, ‘Many’ Models Expected
  9. SK Hynix Overtakes Samsung to Become South Korea's Most Valuable Company
  10. WhiteBIT Receives MiCA Licence in Austria as EU Deadline Nears
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.