Together, the two hacking tools show that the market for sophisticated malware capable of stealing data and cryptocurrency wallet information is flourishing, researchersTogether, the two hacking tools show that the market for sophisticated malware capable of stealing data and cryptocurrency wallet information is flourishing, researchers

Researchers uncover iPhone spyware capable of penetrating millions of devices

2026/03/19 12:28
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

A powerful software exploit capable of penetrating and stealing information from potentially hundreds of millions of Apple iPhones was planted on dozens of websites in Ukraine in recent weeks, researchers said on Wednesday, March 18.

The discovery marks the second time this month that researchers have found spyware targeting iPhones and other Apple devices. Together, the two hacking tools show that the market for sophisticated malware capable of stealing data and cryptocurrency wallet information is flourishing, researchers said.

Researchers with cyber firm Lookout, mobile security firm iVerify and Alphabet’s Google published coordinated analyses of the malware they dubbed “Darksword.” On March 3, Google and iVerify revealed a separate powerful iPhone spyware called “Coruna.” Researchers found Darksword hosted on the same servers.

“There’s now a verified pipeline of recent exploits… that have ended up in the hands of potentially criminal entities with a financial focus,” said Justin Albrecht, principal researcher with Lookout.

Google flags wide-ranging hacking campaign

Google said its researchers observed multiple commercial vendors and suspected state-linked hackers using Darksword in distinct campaigns against targets in Saudi Arabia, Turkey, Malaysia and Ukraine.

The campaigns in Malaysia and Turkey were associated with Turkish commercial surveillance vendor PARS Defense, Google said. PARS Defense did not respond to a request for comment.

According to iVerify and Lookout, researchers discovered the malware being delivered to iPhone users running iOS versions 18.4 to 18.6.2 who visited one of dozens of Ukrainian websites. Apple released those versions between March and August 2025.

It’s not clear how many iPhones are vulnerable to Darksword attacks, the researchers said. Apple has released multiple fixes for the underlying bugs attackers used to make Darksword. Nevertheless, many people don’t install iPhone updates, and an estimated 220 million to 270 million iPhones still run exposed iOS versions, according to iVerify and Lookout, which based the figures on public estimates. Google did not share its findings ahead of Wednesday’s report.

An Apple spokesperson said the exploits targeted “out-of-date software,” and that the underlying vulnerabilities have been addressed across multiple updates over the last several years for users running the latest versions of their devices’ operating systems.

“Keeping software up to date remains the single most important thing users can do to maintain the high security of their Apple devices,” the spokesperson said.

Additionally, all malicious domains identified by Google are blocked by Apple Safe Browsing in the Safari web browser to prevent further exploitation, the spokesperson said.

The discovery of two distinct powerful iOS exploits this month suggests a robust ecosystem for tools that were previously limited primarily to state-level intelligence operations, said Rocky Cole, co-founder and COO of iVerify.

Researchers said they discovered the vulnerabilities because of sloppy security mistakes not common in state-linked iPhone hacking.

“The fact that they don’t care if it gets burned, and that they’re using them in mass attacks with poor (operational security), that says a lot about how much they value these tools,” Cole said. “They’re not overly precious about them being exposed.”

Darksword was found on the internet servers that suspected Russian operators of Coruna used, researchers with iVerify and Lookout said in findings and interviews ahead of Wednesday’s release. – Rappler.com

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

OpenClaw AI Agent Takes China by Storm: Understanding the Viral Phenomenon

OpenClaw AI Agent Takes China by Storm: Understanding the Viral Phenomenon

OpenClaw AI agent dominates China with Baidu and Tencent hosting public events, but security warnings and rising token costs present challenges. The post OpenClaw
Share
Blockonomi2026/03/19 20:07
UK FCA Plans to Waive Some Rules for Crypto Companies: FT

UK FCA Plans to Waive Some Rules for Crypto Companies: FT

The post UK FCA Plans to Waive Some Rules for Crypto Companies: FT appeared on BitcoinEthereumNews.com. The U.K.’s Financial Conduct Authority (FCA) has plans to waive some of its rules for cryptocurrency companies, according to a Financial Times (FT) report on Wednesday. However, in another areas the FCA intends to tighten the rules where they pertain to industry-specific risks, such as cyber attacks. The financial watchdog wishes to adapt its existing rules for financial service companies to the unique nature of cryptoassets, the FT reported, citing a consultation paper published Wednesday. “You have to recognize that some of these things are very different,” David Geale, the FCA’s executive director for payments and digital finance, said in an interview, according to the report, adding that a “lift and drop” of existing traditional finance rules would not be effective with crypto. One such area that may be handled differently is the stipulation that a firm “must conduct its business with integrity” and “pay due regard to the interest of its customers and treat them fairly.” Crypto companies would be given less strict requirements than banks or investment platforms on rules concerning senior managers, systems and controls, as cryptocurrency firms “do not typically pose the same level of systemic risk,” the FCA said. Firms would also not have to offer customers a cooling off period due to the voltatile nature of crypto prices, nor would technology be classed as an outsourcing arrangement requiring extra risk management. This is because blockchain technology is often permissionless, meaning anyone can participate without the input of an intermediary. Other areas of crypto regulation remain undecided. The FCA has plans to fully integrate cryptocurrency into its regulatory framework from 2026. Source: https://www.coindesk.com/policy/2025/09/17/uk-fca-plans-to-waive-some-rules-for-crypto-companies-ft
Share
BitcoinEthereumNews2025/09/18 04:15
Sweet Niblets! Official Trailer Drops For ‘Hannah Montana 20th Anniversary Special’

Sweet Niblets! Official Trailer Drops For ‘Hannah Montana 20th Anniversary Special’

Disney+ and Hulu dropped the official trailer for the highly anticipated “Hannah Montana 20th Anniversary Special.” “Hannah Montana 20th Anniversary Special” will
Share
TechFinancials2026/03/19 19:57