DarkSword exploit compromises iOS 18.4-18.7 devices, targeting cryptocurrency wallets including Coinbase, Binance, and MetaMask. Update to iOS 26.3 now. The postDarkSword exploit compromises iOS 18.4-18.7 devices, targeting cryptocurrency wallets including Coinbase, Binance, and MetaMask. Update to iOS 26.3 now. The post

DarkSword Malware Strikes iOS: Crypto Wallets Under Attack

2026/03/20 21:02
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

Key Takeaways

  • DarkSword compromises iOS versions 18.4 through 18.7, exfiltrating cryptocurrency assets and sensitive information.
  • Ghostblade spyware focuses on popular exchanges like Coinbase, Binance, Kraken, and wallets such as Ledger and MetaMask.
  • Infection occurs through malicious websites requiring zero user interaction to compromise devices.
  • Malware payloads automatically erase themselves after successfully extracting victim data.
  • iOS 26.3 update addresses vulnerabilities; Lockdown Mode provides additional defense against DarkSword.

Cybersecurity researchers have uncovered DarkSword, a sophisticated exploit chain compromising Apple devices running iOS versions 18.4 to 18.7. This attack framework utilizes six previously unknown zero-day security flaws to deploy surveillance malware on targeted iPhones. Active campaigns have been detected across Saudi Arabia, Ukraine, Malaysia, and Turkey, indicating widespread deployment.

The DarkSword framework installs data-stealing malware capable of harvesting authentication credentials, communication records, and geolocation data. Cryptocurrency applications and digital wallets represent primary targets for this malicious campaign. Victims become infected simply by visiting weaponized web pages, requiring no clicks or downloads.

Security analysts have documented three distinct malware variants delivered via DarkSword: Ghostblade, Ghostknife, and Ghostsaber. These payloads rapidly extract targeted information before automatically removing themselves from infected systems. Evidence suggests both commercial surveillance companies and government-sponsored hacking groups are utilizing DarkSword in their operations.

Ghostblade Malware Hunts Cryptocurrency Applications

The Ghostblade payload distributed through DarkSword systematically scans compromised iOS devices for cryptocurrency exchange apps. Its target list encompasses leading trading platforms: Coinbase, Binance, Kraken, Kucoin, OKX, and MEXC. Additionally, it searches for prominent wallet software including Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe.

Beyond digital currency theft, Ghostblade harvests text messages, iMessages, phone logs, and contact lists from infected devices. The spyware extracts Wi-Fi passwords, Safari browser cookies, web history, and GPS coordinates. It further accesses Apple Health records, photo libraries, and conversations from messaging platforms like Telegram and WhatsApp.

Ghostblade executes a hit-and-run strategy, removing temporary artifacts and self-destructing after completing data exfiltration. This rapid execution minimizes forensic evidence left on compromised devices. The deployment of Ghostblade through DarkSword demonstrates escalating threats facing cryptocurrency holders.

Worldwide Campaign Distribution and Technical Operation

DarkSword deployment has been documented through weaponized websites and hijacked government web portals. Saudi Arabian victims were lured through a counterfeit Snapchat-themed page hosting the DarkSword exploit. The attack framework generates hidden iframes and retrieves remote code execution modules to inject malware payloads.

Various remote code execution exploits within DarkSword target distinct iOS versions, exploiting memory handling flaws and pointer authentication bypass weaknesses. The loader mechanism occasionally struggles with device version identification, suggesting accelerated development timelines. Nevertheless, DarkSword successfully delivers terminal payloads including Ghostknife and Ghostsaber across affected devices.

Security teams disclosed these vulnerabilities to Apple during late 2025, with remediation patches released in iOS 26.3. Domains associated with DarkSword distribution have been incorporated into browser Safe Browsing databases. iPhone owners should immediately install iOS updates or activate Lockdown Mode to defend against DarkSword exploitation.

DarkSword represents a critical security challenge for iOS cryptocurrency users worldwide. The exploit’s swift proliferation among diverse threat actors demonstrates heightened risks to digital financial holdings. Its comprehensive targeting of exchanges, wallets, and personal information emphasizes the urgency of applying available security patches.

The post DarkSword Malware Strikes iOS: Crypto Wallets Under Attack appeared first on Blockonomi.

Market Opportunity
4 Logo
4 Price(4)
$0.009002
$0.009002$0.009002
+13.56%
USD
4 (4) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

TrendX Taps Trusta AI to Develop Safer and Smarter Web3 Network

TrendX Taps Trusta AI to Develop Safer and Smarter Web3 Network

The purpose of collaboration is to advance the Web3 landscape by combining the decentralized infrastructure of TrendX with AI-led capabilities of Trusta AI.
Share
Blockchainreporter2025/09/18 01:07
Top 3 Cryptos Under $1 That Could Hit $10 By 2028

Top 3 Cryptos Under $1 That Could Hit $10 By 2028

The post Top 3 Cryptos Under $1 That Could Hit $10 By 2028 appeared on BitcoinEthereumNews.com. Investors are increasingly looking for tokens with long-term value in 2025. While Cardano (ADA) keeps showing strong performance in the market, and Dogecoin (DOGE) keeps holding onto community-led speculation, a new token, Mutuum Finance (MUTM), is building something much larger.  Unlike speculative memecoins, Mutuum Finance is building real utility in the shape of its decentralized lending and borrowing protocol as it positions itself to be a fundamentals-driven project that will go way, way beyond the $1 threshold. As the market anticipates the next cycle, the following three coins, Cardano (ADA), Dogecoin (DOGE), and Mutuum Finance (MUTM), are gaining traction for their potential surge to $10 by 2028 but MUTM’s unique value proposition shines extremely brightly. Cardano Holds Firm Amid Market Turbulence Cardano (ADA) is trading at $0.86 currently, level with the rest of the market as investors weigh in upcoming network upgrades against shifting macroeconomic trends. Cardano (ADA) retains its place as one of the flagship layer-1 projects focused on scalability and sustainability, but market participants are increasingly turning towards newer protocols with stronger growth drivers, and Mutuum Finance stands as a better choice in the DeFi market as it evolves. Dogecoin Halts After Rally as Market Considers Next Step Dogecoin (DOGE) is at $0.27, still considerably above its recent level of support after a very active rally. There is resistance at $0.30, and support at the $0.22-$0.25 level, which means probable consolidation unless new buying pressure is seen. Volume has reduced somewhat, suggesting some profit-taking by traders as they await better signals. In comparison to DOGE, analysts are now equating Mutuum Finance as having greater potential for gains. Mutuum Finance: Phase 6 Mark Presale Mutuum Finance has enjoyed a phenomenal level of traction in presale with more than 16,370 investors buying coins and more than $15.9 million raised thus…
Share
BitcoinEthereumNews2025/09/18 15:41
Best Sit and Go Poker Sites

Best Sit and Go Poker Sites

The post Best Sit and Go Poker Sites appeared on BitcoinEthereumNews.com. Like its name implies, Sit and Go tournaments, widely popular as SNG poker events, allow players to jump into the action immediately, appealing to players who prefer not to wait for scheduled games.  These events start as soon as the seats are filled rather than at a set time, ensuring a more spontaneous and fast-paced tournament experience than traditional events with specific start times.  That alone explains why the format has grown increasingly popular among tournament crushers, particularly those with busy schedules. Thankfully, some poker sites offer SNG poker format, delivering the flexibility and convenience that many players crave. But the real question is: which among these platforms offer the most rewarding SNG poker experience? Our team of experts provides answers to that question in this article by recommending one of the best Sit and Go poker sites suitable for both newbies and professionals alike. What is SNG Poker? SNG poker is a tournament format defined by its instant start once the required number of players registers. Unlike scheduled multi-table tournaments, there is no waiting for a specific time. The game kicks off as soon as all seats are taken, typically accommodating six, nine, or ten players. Each entrant pays a fixed buy-in that forms the prize pool. Blinds increase at set intervals, creating pressure and pushing players to adjust strategies as the game progresses. This structure makes the format appealing to those seeking a balance between cash games and longer multi-table events. However, prize distribution depends on the format. In a nine-player setup, for instance, the top three positions typically share the pool, with the largest portion awarded to first place. Heads-up versions pay the entire prize pool to the winner, while other variations distribute rewards across multiple seats. This predictability in payouts adds clarity to bankroll management. The…
Share
BitcoinEthereumNews2025/09/18 08:34