BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Russian Hackers Use DarkSword to Target iPhones

Russian FSB-linked hackers now deploy DarkSword iOS exploit via Atlantic Council phishing emails.

  • A Russian state-sponsored hacking group is now using the leaked DarkSword iOS exploit kit in targeted email attacks.
  • The campaign spoofed the Atlantic Council to deliver malware, with one prominent Russian opposition figure among the targets.
  • Enterprise security firm Proofpoint noted a significant increase in the volume of such attacks over the past two weeks.
  • Apple has begun sending urgent Lock Screen notifications to users on older iOS versions to warn of the threat.

A Russian state-sponsored threat group known as TA446, linked to the FSB, is now targeting iOS devices using the powerful DarkSword exploit kit embedded within phishing emails, according to Proofpoint. This campaign, active in late March 2026, uses fake invitations from the Atlantic Council to implant malicious software.

- Advertisement -

Consequently, this represents a major escalation in the group’s tactics, which previously focused on credential harvesting. Targets now include government agencies, think tanks, and financial institutions, as Proofpoint and Malfors detailed.

The emails successfully delivered the GHOSTBLADE dataminer and MAYBEROBOT backdoor malware using the sophisticated kit. One recipient of these attack emails was Leonid Volkov, a noted Russian opposition leader.

However, automated analysis suggests some security tools saw only a decoy PDF. The server-side filtering likely delivered the exploit kit exclusively to iPhone browsers.

Proofpoint stated, “We have not previously observed TA446 target users’ iCloud accounts or Apple devices, but the adoption of the leaked DarkSword iOS exploit kit has now enabled the actor to target iOS devices.” Evidence linking the group to DarkSword includes malware referencing a known TA446-controlled domain.

- Advertisement -

A urlscan.io result revealed the technical components served by the domain. Meanwhile, the campaign’s wide targeting has raised concerns about opportunistic exploitation.

Simultaneously, Apple is issuing direct Lock Screen warnings to users on outdated iOS versions to update and block the threat. Meanwhile, as a VirusTotal file shows, the leak of DarkSword’s newer version on GitHub has alarmed experts.

Justin Albrecht, principal researcher at Lookout, warned about the kit’s commoditization. He added, “DarkSword refutes the common belief that iPhones are immune to cyber threats, and that advanced mobile attacks are only used in targeted efforts against governments and high-ranking officials.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Circle unfreezes wallets in sealed USDC freeze case.

Circle has unfrozen five of 16 business wallets containing its USDC stablecoin that were...

Senator Warren Demands Probe Into Chinese Bitcoin Miner

Senator Elizabeth Warren has requested the US Commerce Department explain its handling of Bitmain-related...

Bitcoin ETFs See First Weekly Outflows Since February

Spot Bitcoin ETFs registered nearly $300 million in net outflows for the week ending...

Ripple CEO: Stablecoins Are Crypto’s ‘ChatGPT Moment’

Ripple CEO Brad Garlinghouse predicts stablecoins will be the "ChatGPT moment" for business payments,...

Exclusive: Morgan Stanley plans cheapest US Bitcoin ETF

Morgan Stanley has filed for a spot Bitcoin ETF with a proposed fee of...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading