iPhone spyware DarkSword hits Malaysia, exposing spread of sophisticated hacking tools
A new iPhone spyware operation called DarkSword has been discovered targeting users in Malaysia, Ukraine, Saudi Arabia, and Turkey. Researchers from iVerify, Google, and Lookout uncovered the spyware, which is spread through compromised websites using a "watering hole" tactic to silently infect iPhones.

Briefing Summary
AI-generatedA new iPhone spyware operation called DarkSword has been discovered targeting users in Malaysia, Ukraine, Saudi Arabia, and Turkey. Researchers from iVerify, Google, and Lookout uncovered the spyware, which is spread through compromised websites using a "watering hole" tactic to silently infect iPhones. DarkSword can steal sensitive data, including messages, call logs, location history, and health records. Google's Threat Intelligence Group identified multiple users of the DarkSword exploit chain dating back to November 2023, including commercial surveillance vendors like PARS Defence and a suspected Russian espionage group, UNC6353. The discovery highlights the increasing proliferation of sophisticated mobile hacking tools among commercial and potentially state-linked actors.
Article analysis
Model · rule-basedKey claims
5 extractedMultiple commercial surveillance vendors and suspected state-linked actors had used DarkSword.
DarkSword could compromise vulnerable iPhones and siphon off sensitive data.
Researchers at iVerify, Google, and Lookout uncovered DarkSword.
DarkSword was observed targeting entities in Malaysia, Ukraine, Saudi Arabia and Turkey.
Malaysian users are among victims targeted by iPhone spyware operation DarkSword.