The ' DarkSword ' attack technique can steal hidden messages, contacts, stored credentials, cryptocurrency wallets, and more on iPhones running iOS 18.4 to 18.6.2 . If you've been holding off on updating to iOS 26, now might be the time to do so. On Wednesday, security researchers published findings on a new hacking tool that targets iPhones running iOS 18.4 to 18.6.2, as previously reported by Wired.
See also: Stryker: Iranian hackers used stolen credentials

The exploit ‘DarkSword’ allows malicious users to collect personal information from iPhones that visit malicious links and has already been used by Russian hackers.
Google's Threat Intelligence Team worked with cybersecurity firms Lookout and iVerify to analyze the attack, which could affect up to 270 million devices still running affected versions of iOS 18. When a user accesses a compromised website, Google says DarkSword uses 'six different vulnerabilities' to carry out an attack targeting Safari, giving malicious users the ability to collect text messages, contacts, saved credentials, iCloud files, photos, cryptocurrency wallets, call logs, location history, and more.
Google says it reported the vulnerability to Apple in late 2025. In an emailed statement to The Verge, Apple spokesperson Sarah O'Rourkeconfirmed that Apple had patched all of the "underlying vulnerabilities" in iOS last year before issuing an "emergency software update last week for older devices that could not be updated to more recent versions of iOS."
See also: Hackers from Iran target the US and other targets

DarkSword uses ahit-and-runthat allows attackers to "extract high-value data and disappear before traditional detection methods can respond," according to Lookout. Google says suspected Russian state hackers used DarkSword to target users in Ukraine, Saudi Arabia, Malaysia , and Turkey.
These hackers were also discovered to be using an iOS exploit kit called Coruna, which Google highlighted in a report earlier this month. iVerify notes that the Russian-linked hackers left the DarkSword code 'unencrypted, unprotected, and easily accessible,' making it easy for other malicious users to access and potentially reuse it.
See also: Iranian hackers claim responsibility for wiper attack on Stryker

Google, Lookout and iVerify found that the attack does not affect users in Lockdown Mode, an 'extreme' security feature for the iPhone that protects journalists, activists and politicians from targeted attacks. Apple and Google have also blocked the malicious links used in the DarkSword attacks in Safari and Chrome.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
