Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Elon Musk with folded arms flanked by a giant Bitcoin coin, Tesla electric car, and SpaceX rocket launch
    Elon Musk’s Tesla and SpaceX Still Hold Over 30,000 Bitcoin: Why Is He Not Selling?
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto What the Record Actually Shows
    Is ‘Paul Le Roux’ Really Satoshi Nakamoto? What the Record Actually Shows
    Bitget exchange coin token set in front of a blurred FTX building backdrop.
    Is Bitget the Next FTX? What the $351.6 Million Hack Does and Doesn’t Have in Common
    Gold Bitcoin BTC coin standing vertically in front of a rising green financial candlestick chart
    Inside Bitcoin’s September 2026 Rally: BTC Reclaiming $87K, $2B in ETF Inflows and a Short Squeeze
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
    CLARITY Act Fails 49-50 in US Senate as SEC & CFTC Move Ahead on Crypto Rules Within 48 Hours
  • Opinion
    OpinionShow More
    Donald Trump speaking at a presidential podium with the White House and U.S. Capitol building in the background.
    Trump Just Declared the Super Intelligence Era in the “Unites States.” So Who Controls It?
    Comparison of Bybit 12-hour, Bitget 85-hour, and WazirX 463-day response timers
    Bitget, Bybit Paid in Hours; WazirX Lost Least in Hacks at $235M, Held Users Hostage for 463 Days
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

DarkSword iOS Attacks: Compromised Websites Puts User’s Crypto at Risk

Ledger CTO says it targets iOS globally, using compromised sites to steal data, monitor activity, and take full control of devices instantly.

Written By Kenrodgers Fabian
Fact Checked by Gopal Solanky
Published 2026-03-19
Make The Crypto Times preferred on GoogleGoogle
DarkSword iOS Attacks Compromised Websites Puts User’s Crypto at Risk

Key Highlights

  • DarkSword exploits iOS flaws to fully compromise devices, targeting users worldwide.
  • Malware families like GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER steal data and monitor activity.
  • Visiting a compromised site can trigger full device control without any user action.

A new iOS exploit dubbed DarkSword is actively targeting users worldwide, putting crypto assets and personal data at immediate risk. The attack leverages multiple zero-day vulnerabilities in iOS versions 18.4 through 18.7, delivering full device compromise without any user interaction. 

According to Charles Guillemet, CTO at Ledger, DarkSword is “already deployed at scale via watering-hole attacks” and has affected users in Ukraine, Saudi Arabia, Turkey, and Malaysia. One visit to a compromised website can trigger full surveillance, data exfiltration, and total device control. This marks a shift from rare, targeted exploits to industrialized, mass-level attacks.

The CTO also highlighted that this emerges just days after Google’s March 3, 2026 disclosure of Coruna—a leaked nation-state kit exploiting 23 flaws across iOS 13-17.2.1, which compromised thousands through similar web lures. 

🚨Only days after Coruna, one of the first large-scale iOS exploit kits, DarkSword is already being exploited in the wild.

Coruna showed the pattern: state-grade iOS exploits don’t stay in government hands. They leak, spread, and end up in broader ecosystems. One visit to a…

— Charles Guillemet (@P3b7_) March 18, 2026

Google’s Threat Intelligence Group (GTIG) confirmed in a blog post that DarkSword has been around since November 2025 and is being used by commercial surveillance providers and state-sponsored actors.

As per the group, the malware chain makes use of a number of malware families, including GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER.

Each malware variant infiltrates different types of data, ranging from messages and browser history to microphone recordings. Besides, the exploit fully bypasses iOS security layers, including WebContent and GPU sandbox protections.

How DarkSword works

DarkSword takes advantage of six separate weaknesses in iOS to take over a device. It starts by exploiting Safari’s JavaScript engine to run malicious code. Older iPhones are hit through one flaw, while newer versions rely on another, both combined with a method to bypass Apple’s security checks. 

This gives attackers deep access to the device’s core system. From there, the exploit breaks out of Safari’s restricted environment and moves into higher-level system processes, letting it run the final malware. 

Finally, it escalates privileges to gain full control of the phone. Remarkably, the entire attack runs through JavaScript, so attackers don’t need to install any unsigned apps or files.

Targeted campaigns and malware families

Several groups have been adapting DarkSword for their own attacks. UNC6748 targeted users in Saudi Arabia through fake Snapchat websites, using GHOSTKNIFE to steal accounts and monitor activity. PARS Defense focused on users in Turkey and Malaysia, deploying GHOSTSABER along with encrypted exploits and tools to track devices. 

Meanwhile, UNC6353, believed to be linked to Russian espionage, went after Ukrainian websites with GHOSTBLADE, a tool designed to collect data. While GHOSTBLADE doesn’t maintain ongoing access, it still deletes crash logs to hide its presence.

Experts warn that DarkSword marks a new level of iOS threats. Unlike older attacks, it can compromise anyone who visits legitimate websites. Therefore, users should assume their devices could be at risk and exercise extreme caution at all times.

Also Read: Coinbase Commerce Faces Backlash Over ‘Unsafe’ Seed Phrase Tool

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Base Vault Hack $6M in wstETH Drained After Attacker Gains Whitelist Access
Base Vault Hack: $6M in wstETH Drained After Attacker Gains Whitelist Access
Smartphone displaying Starknet (STRK) price chart in front of Starknet office wall signage.
Starknet STRK Jumps 22.9% as Trading Volume Surges 
Smartphone displaying the Ondo Finance logo in front of Ondo wall signage.
Ondo Tokenized Value Hits $4B Across 10 Networks
Smartphone displaying the Aptos logo next to a magnifying glass showing the Aptos emblem in front of a red market chart.
Fact Check: Aptos Shutting Down the Chain in 6 Months?
Charles Hoskinson wearing glasses and a suit jacket seated in front of an IOHK logo backdrop.
Hoskinson Disputes Midnight’s $1.81 NIGHT Price Peak on CoinMarketCap

Find Us on Socials

You may also like

Gala Games, Base, and Uniswap physical cryptocurrency tokens arranged in a row in front of a market chart.

GoldPesa’s GPXHooks Allegedly Drained for $114K in Base Exploit

NEAR Protocol (NEAR) physical coin standing next to stacked gold coins and a crypto wallet.

NEAR Intents Ends Exploit Probe After $3.8 Million Is Returned

Blast Layer 2 protocol logo in neon yellow against a dark background.

Blast Shuts Down Ethereum L2 as Operating Costs Exceed Revenue

Drift Protocol logo and wordmark set against a dark digital background.

Drift Opens DFX Claims at 1 Cent Per Token After April Exploit

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Masthead
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information