DarkSword exploit compromises iOS 18.4-18.7 devices, targeting cryptocurrency wallets including Coinbase, Binance, and MetaMask. Update to iOS 26.3 now. The postDarkSword exploit compromises iOS 18.4-18.7 devices, targeting cryptocurrency wallets including Coinbase, Binance, and MetaMask. Update to iOS 26.3 now. The post

DarkSword Malware Strikes iOS: Crypto Wallets Under Attack

2026/03/20 21:02
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen [email protected] üzerinden bizimle iletişime geçin.

Key Takeaways

  • DarkSword compromises iOS versions 18.4 through 18.7, exfiltrating cryptocurrency assets and sensitive information.
  • Ghostblade spyware focuses on popular exchanges like Coinbase, Binance, Kraken, and wallets such as Ledger and MetaMask.
  • Infection occurs through malicious websites requiring zero user interaction to compromise devices.
  • Malware payloads automatically erase themselves after successfully extracting victim data.
  • iOS 26.3 update addresses vulnerabilities; Lockdown Mode provides additional defense against DarkSword.

Cybersecurity researchers have uncovered DarkSword, a sophisticated exploit chain compromising Apple devices running iOS versions 18.4 to 18.7. This attack framework utilizes six previously unknown zero-day security flaws to deploy surveillance malware on targeted iPhones. Active campaigns have been detected across Saudi Arabia, Ukraine, Malaysia, and Turkey, indicating widespread deployment.

The DarkSword framework installs data-stealing malware capable of harvesting authentication credentials, communication records, and geolocation data. Cryptocurrency applications and digital wallets represent primary targets for this malicious campaign. Victims become infected simply by visiting weaponized web pages, requiring no clicks or downloads.

Security analysts have documented three distinct malware variants delivered via DarkSword: Ghostblade, Ghostknife, and Ghostsaber. These payloads rapidly extract targeted information before automatically removing themselves from infected systems. Evidence suggests both commercial surveillance companies and government-sponsored hacking groups are utilizing DarkSword in their operations.

Ghostblade Malware Hunts Cryptocurrency Applications

The Ghostblade payload distributed through DarkSword systematically scans compromised iOS devices for cryptocurrency exchange apps. Its target list encompasses leading trading platforms: Coinbase, Binance, Kraken, Kucoin, OKX, and MEXC. Additionally, it searches for prominent wallet software including Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe.

Beyond digital currency theft, Ghostblade harvests text messages, iMessages, phone logs, and contact lists from infected devices. The spyware extracts Wi-Fi passwords, Safari browser cookies, web history, and GPS coordinates. It further accesses Apple Health records, photo libraries, and conversations from messaging platforms like Telegram and WhatsApp.

Ghostblade executes a hit-and-run strategy, removing temporary artifacts and self-destructing after completing data exfiltration. This rapid execution minimizes forensic evidence left on compromised devices. The deployment of Ghostblade through DarkSword demonstrates escalating threats facing cryptocurrency holders.

Worldwide Campaign Distribution and Technical Operation

DarkSword deployment has been documented through weaponized websites and hijacked government web portals. Saudi Arabian victims were lured through a counterfeit Snapchat-themed page hosting the DarkSword exploit. The attack framework generates hidden iframes and retrieves remote code execution modules to inject malware payloads.

Various remote code execution exploits within DarkSword target distinct iOS versions, exploiting memory handling flaws and pointer authentication bypass weaknesses. The loader mechanism occasionally struggles with device version identification, suggesting accelerated development timelines. Nevertheless, DarkSword successfully delivers terminal payloads including Ghostknife and Ghostsaber across affected devices.

Security teams disclosed these vulnerabilities to Apple during late 2025, with remediation patches released in iOS 26.3. Domains associated with DarkSword distribution have been incorporated into browser Safe Browsing databases. iPhone owners should immediately install iOS updates or activate Lockdown Mode to defend against DarkSword exploitation.

DarkSword represents a critical security challenge for iOS cryptocurrency users worldwide. The exploit’s swift proliferation among diverse threat actors demonstrates heightened risks to digital financial holdings. Its comprehensive targeting of exchanges, wallets, and personal information emphasizes the urgency of applying available security patches.

The post DarkSword Malware Strikes iOS: Crypto Wallets Under Attack appeared first on Blockonomi.

Piyasa Fırsatı
4 Logosu
4 Fiyatı(4)
$0.008853
$0.008853$0.008853
+11.68%
USD
4 (4) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Coinbase Joins Ethereum Foundation to Back Open Intents Framework

Coinbase Joins Ethereum Foundation to Back Open Intents Framework

Coinbase Payments has joined the Open Intents Framework as a core contributor, working alongside Ethereum Foundation and other major players. The initiative aims to simplify complex multi-chain interactions through automated solver technology. The post Coinbase Joins Ethereum Foundation to Back Open Intents Framework appeared first on Coinspeaker.
Paylaş
Coinspeaker2025/09/18 02:43
Solana’s (SOL) Recent Rally May Impress, But Investors Targeting Life-Changing ROI Are Looking Elsewhere

Solana’s (SOL) Recent Rally May Impress, But Investors Targeting Life-Changing ROI Are Looking Elsewhere

The post Solana’s (SOL) Recent Rally May Impress, But Investors Targeting Life-Changing ROI Are Looking Elsewhere appeared on BitcoinEthereumNews.com. Solana’s (SOL) latest rally has attracted investors from all over, but the bigger story for vision-minded investors is where the next surges of life-altering returns are heading.  As Solana continues to see high levels of ecosystem usage and network utilization, the stage is slowly being set for Mutuum Finance (MUTM).  MUTM is priced at $0.035 in its fast-growing presale. Price appreciation of 14.3% is what the investors are going to anticipate in the next phase. Over $15.85 million has been raised as the presale keeps gaining momentum. Unlike the majority of the tokens surfing short-term waves of hype, Mutuum Finance is becoming a utility-focused choice with more value potential and therefore an increasingly better option for investors looking for more than price action alone. Solana Maintains Gains Near $234 As Speculation Persists Solana (SOL) is trading at $234.08 currently, holding its 24hr range around $234.42 to $248.19 as it illustrates the recent trend. The token has recorded strong seven-day gains of nearly 13%, far exceeding most of its peers, as it is supported by rising volume and institutional buying. Resistance is at $250-$260, and support appears to be at $220-$230, and thus these are significant levels for potential breakout or pullback.  However, new DeFi crypto Mutuum Finance, is being considered by market watchers to have more upside potential, being still in presale.  Mutuum Finance Phase 6 Presale Mutuum Finance is currently in Presale Stage 6 and offering tokens for $0.035. Presale has been going on very fast, and investors have raised over $15.85 million. The project also looks forward to a USD-pegged stablecoin on the Ethereum blockchain for convenient payments and as a keeper of long-term value. Mutuum Finance is a dual-lending, multi-purpose DeFi platform that benefits borrowers and lenders alike. It provides the network to retail as well as…
Paylaş
BitcoinEthereumNews2025/09/18 06:23
How will this Middle East war reshape your assets in 12 months?

How will this Middle East war reshape your assets in 12 months?

Original post: @radigancarter Compiled by: Big Claws | PANew Lobster I've been thinking about this issue on and off for about a week, while also dealing with the
Paylaş
PANews2026/03/23 12:12