A new cybersecurity alert highlights the discovery of the DarkSword iOS exploit kit, which has expanded to over 100 web properties being operated by at least seven different groups. This exploit targets iPhone and iPad users on iOS versions 18.4 to 18.7, harvesting credentials and other sensitive data through a chain of six vulnerabilities. The DarkSword operation, linked to a suspected Chinese-speaking actor, uses spoofed webpages to lure victims and steal information via the GHOSTBLADE implant.
As victims interact with these fake pages, their iCloud, keychain, and Wi-Fi data are extracted and sent to a central collector. The report emphasizes the urgency of updating iOS devices to mitigate risks, while highlighting the need for vigilance against phishing attacks.