NEWSAR
Multi-perspective news intelligence
SRCSouth China Morning Post
LANGEN
LEANCenter-Right
WORDS193
ENT12
TUE · 2026-03-24 · 12:31 GMTBRIEF NSR-2026-0324-32831
News/iPhone spyware DarkSword hits Malaysia, exposing spread of s…
NSR-2026-0324-32831News Report·EN·National Security

iPhone spyware DarkSword hits Malaysia, exposing spread of sophisticated hacking tools

A new iPhone spyware operation called DarkSword has been discovered targeting users in Malaysia, Ukraine, Saudi Arabia, and Turkey. Researchers from iVerify, Google, and Lookout uncovered the spyware, which is spread through compromised websites using a "watering hole" tactic to silently infect iPhones.

Ushar DanieleSouth China Morning PostFiled 2026-03-24 · 12:31 GMTLean · Center-RightRead · 1 min
iPhone spyware DarkSword hits Malaysia, exposing spread of sophisticated hacking tools
South China Morning PostFIG 01
Reading time
1min
Word count
193words
Sources cited
3cited
Entities identified
12entities
Quality score
100%
§ 01

Briefing Summary

AI-generated
NEWSAR · AI

A new iPhone spyware operation called DarkSword has been discovered targeting users in Malaysia, Ukraine, Saudi Arabia, and Turkey. Researchers from iVerify, Google, and Lookout uncovered the spyware, which is spread through compromised websites using a "watering hole" tactic to silently infect iPhones. DarkSword can steal sensitive data, including messages, call logs, location history, and health records. Google's Threat Intelligence Group identified multiple users of the DarkSword exploit chain dating back to November 2023, including commercial surveillance vendors like PARS Defence and a suspected Russian espionage group, UNC6353. The discovery highlights the increasing proliferation of sophisticated mobile hacking tools among commercial and potentially state-linked actors.

Confidence 0.90Sources 3Claims 5Entities 12
§ 02

Article analysis

Model · rule-based
Framing
National Security
Technology
Tone
Measured
AI-assessed
CalmNeutralAlarmist
Factuality
0.80 / 1.00
Factual
LowHigh
Sources cited
3
Well sourced
FewMany
§ 03

Key claims

5 extracted
01

Multiple commercial surveillance vendors and suspected state-linked actors had used DarkSword.

factualGoogle’s Threat Intelligence Group (GTIG)
Confidence
1.00
02

DarkSword could compromise vulnerable iPhones and siphon off sensitive data.

factualResearchers at iVerify, working with Google and Lookout
Confidence
1.00
03

Researchers at iVerify, Google, and Lookout uncovered DarkSword.

factual
Confidence
1.00
04

DarkSword was observed targeting entities in Malaysia, Ukraine, Saudi Arabia and Turkey.

factual
Confidence
1.00
05

Malaysian users are among victims targeted by iPhone spyware operation DarkSword.

factual
Confidence
1.00
§ 04

Full report

1 min read · 193 words
Malaysian users are among victims targeted by a newly uncovered iPhone spyware operation that researchers say was used by multiple threat actors across countries, in a sign that sophisticated mobile-hacking tools are spreading through a murkier commercial and criminal ecosystem.The spyware, known as DarkSword, was observed targeting entities in Malaysia, Ukraine, Saudi Arabia and Turkey, and was uncovered by investigators shortly after they exposed another exploit kit, Coruna, linked to the same infrastructure.Researchers at iVerify, working with Google and Lookout, said DarkSword could compromise vulnerable iPhones through hacked legitimate websites and siphon off highly sensitive data, including messages, call logs, location history, notes and health records.The attack uses a watering hole tactic in which perpetrators compromise websites a victim is likely to visit and use them to silently try to break into the individual’s phone.Google’s Threat Intelligence Group (GTIG) said multiple commercial surveillance vendors and suspected state-linked actors had used DarkSword, including activity linked to Turkish spyware vendor PARS Defence and a suspected Russian espionage group known as UNC6353.“GTIG has identified several different users of the DarkSword exploit chain dating back to November 2025,” Google said in a threat intelligence report last week.
§ 05

Entities

12 identified
§ 06

Keywords & salience

9 terms
iphone spyware
1.00
darksword
0.90
mobile hacking
0.80
spyware
0.70
watering hole attack
0.60
threat actors
0.50
data siphoning
0.50
cybersecurity
0.40
mobile security
0.40
§ 07

Topic connections

Interactive graph
No topic relationship data available yet. This graph will appear once topic relationships have been computed.