TLDR DarkSword hits iOS 18.4–18.7, stealing crypto wallets and personal data. Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more. ExploitTLDR DarkSword hits iOS 18.4–18.7, stealing crypto wallets and personal data. Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more. Exploit

DarkSword Exploit Hits iOS Devices Targeting Crypto Users

2026/03/20 20:50
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen [email protected] üzerinden bizimle iletişime geçin.

TLDR

  • DarkSword hits iOS 18.4–18.7, stealing crypto wallets and personal data.

  • Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more.

  • Exploit triggers via fake sites; no user action needed to infect devices.

  • Final-stage malware self-deletes after stealing sensitive data quickly.

  • Update to iOS 26.3 or enable Lockdown Mode to block DarkSword attacks.

A new iOS exploit chain called DarkSword is actively targeting devices running iOS 18.4 through 18.7. The exploit leverages six zero-day vulnerabilities to install malware on compromised devices. Multiple actors are deploying DarkSword against users in Saudi Arabia, Ukraine, Malaysia and Turkey.

DarkSword delivers malware designed to steal sensitive data, including login credentials, call history and location information. It specifically targets cryptocurrency apps and wallets on infected devices. Users visiting compromised websites can unknowingly trigger the exploit without any interaction.

Cybersecurity researchers have identified several final-stage malware families deployed through DarkSword. These include Ghostblade, Ghostknife, and Ghostsaber, which extract data quickly and self-delete afterward. The campaigns show DarkSword’s adoption by both commercial spyware vendors and state-backed threat actors.

Ghostblade Targets Crypto Exchanges and Wallets

Ghostblade, deployed by DarkSword, actively searches for cryptocurrency exchange applications on iOS devices. It targets major platforms such as Coinbase, Binance, Kraken, Kucoin, OKX, and MEXC. The malware also hunts popular wallets including Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe.

In addition to crypto assets, Ghostblade collects SMS, iMessage, call history, and contacts from the device. It also exfiltrates Wi-Fi credentials, Safari cookies, browsing history, and location information. The malware accesses health data, photos, and messaging history from Telegram and WhatsApp.

Ghostblade operates for short-term data theft, deleting temporary files and terminating itself after extraction. This quick-action design ensures minimal traces remain on the infected device. DarkSword’s ability to deliver Ghostblade highlights the increasing targeting of crypto users.

Global Deployment and Exploit Mechanics

DarkSword has been observed in targeted campaigns using fake websites and compromised government portals. In Saudi Arabia, a Snapchat-themed site was used to infect devices through DarkSword. The exploit chain creates iframes and fetches remote code execution modules to deliver the malware.

Different RCE exploits in DarkSword target specific iOS versions, including memory corruption and PAC bypass vulnerabilities. The loader logic sometimes fails to differentiate device versions, reflecting the tool’s rapid deployment. Despite this, DarkSword consistently installs final-stage payloads like Ghostknife and Ghostsaber.

Researchers reported the vulnerabilities to Apple in late 2025, and patches were included in iOS 26.3. Domains linked to DarkSword delivery are now added to Safe Browsing lists. Users are urged to update iOS devices or enable Lockdown Mode for added protection against DarkSword campaigns.

DarkSword has emerged as a significant threat to cryptocurrency users on iOS devices. The exploit’s rapid adoption by multiple actors signals a growing risk to digital assets. Its targeting of exchanges, wallets, and personal data underscores the need for immediate device updates.

The post DarkSword Exploit Hits iOS Devices Targeting Crypto Users appeared first on CoinCentral.

Piyasa Fırsatı
4 Logosu
4 Fiyatı(4)
$0.007651
$0.007651$0.007651
-1.12%
USD
4 (4) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen [email protected] ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

The Channel Factories We’ve Been Waiting For

The Channel Factories We’ve Been Waiting For

The post The Channel Factories We’ve Been Waiting For appeared on BitcoinEthereumNews.com. Visions of future technology are often prescient about the broad strokes while flubbing the details. The tablets in “2001: A Space Odyssey” do indeed look like iPads, but you never see the astronauts paying for subscriptions or wasting hours on Candy Crush.  Channel factories are one vision that arose early in the history of the Lightning Network to address some challenges that Lightning has faced from the beginning. Despite having grown to become Bitcoin’s most successful layer-2 scaling solution, with instant and low-fee payments, Lightning’s scale is limited by its reliance on payment channels. Although Lightning shifts most transactions off-chain, each payment channel still requires an on-chain transaction to open and (usually) another to close. As adoption grows, pressure on the blockchain grows with it. The need for a more scalable approach to managing channels is clear. Channel factories were supposed to meet this need, but where are they? In 2025, subnetworks are emerging that revive the impetus of channel factories with some new details that vastly increase their potential. They are natively interoperable with Lightning and achieve greater scale by allowing a group of participants to open a shared multisig UTXO and create multiple bilateral channels, which reduces the number of on-chain transactions and improves capital efficiency. Achieving greater scale by reducing complexity, Ark and Spark perform the same function as traditional channel factories with new designs and additional capabilities based on shared UTXOs.  Channel Factories 101 Channel factories have been around since the inception of Lightning. A factory is a multiparty contract where multiple users (not just two, as in a Dryja-Poon channel) cooperatively lock funds in a single multisig UTXO. They can open, close and update channels off-chain without updating the blockchain for each operation. Only when participants leave or the factory dissolves is an on-chain transaction…
Paylaş
BitcoinEthereumNews2025/09/18 00:09
Gold continues to hit new highs. How to invest in gold in the crypto market?

Gold continues to hit new highs. How to invest in gold in the crypto market?

As Bitcoin encounters a "value winter", real-world gold is recasting the iron curtain of value on the blockchain.
Paylaş
PANews2025/04/14 17:12
XRP Multi-Year Accumulation Signals Potential 1000% Breakout

XRP Multi-Year Accumulation Signals Potential 1000% Breakout

The post XRP Multi-Year Accumulation Signals Potential 1000% Breakout appeared on BitcoinEthereumNews.com. XRP Builds Multi-Year Base as Whales Accumulate and Volume
Paylaş
BitcoinEthereumNews2026/03/21 00:04