{"id":28548,"date":"2026-03-23T21:14:12","date_gmt":"2026-03-23T21:14:12","guid":{"rendered":"https:\/\/microvibenews.com\/?p=28548"},"modified":"2026-03-23T21:14:12","modified_gmt":"2026-03-23T21:14:12","slug":"someone-has-publicly-leaked-an-exploit-kit-that-can-hack-millions-of-iphones","status":"publish","type":"post","link":"https:\/\/microvibenews.com\/?p=28548","title":{"rendered":"Someone has publicly leaked an exploit kit that can hack millions of iPhones"},"content":{"rendered":"<p><br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Last week, cybersecurity researchers <a href=\"https:\/\/techcrunch.com\/2026\/03\/18\/russians-caught-stealing-personal-data-from-ukrainians-with-new-advanced-iphone-hacking-tools\/\">uncovered a hacking campaign targeting iPhone users<\/a> that used an advanced hacking tool called DarkSword. Now, someone has leaked a newer version of DarkSword and published it on the code sharing site GitHub.<\/p>\n<p class=\"wp-block-paragraph\">Researchers are warning that this will allow any hacker to easily use the tools to target iPhone users running older versions of Apple\u2019s operating systems who have not yet updated to its latest iOS 26 software. This likely affects hundreds of millions of actively used iPhones and iPads, according to Apple\u2019s own data on out-of-date devices.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis is bad. They are way too easy to repurpose,\u201d Matthias Frielingsdorf, the co-founder of mobile security startup iVerify, told TechCrunch on Monday. \u201cI don\u2019t think that can be contained anymore. So we need to expect criminals and others to start deploying this.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Frielingsdorf said that these new versions of DarkSword spyware share the same infrastructure with the ones he and his iVerify colleagues <a rel=\"nofollow\" href=\"https:\/\/iverify.io\/blog\/darksword-ios-exploit-kit-explained\">analyzed previously<\/a>, although the files are slightly different. The files uploaded to GitHub are uncomplicated, just HTML and JavaScript, he said, meaning anyone can copy and paste them and host them on a server \u201cin a couple minutes to hours.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe exploits will work out of the box,\u201d Frielingsdorf said. \u201cThere is no iOS expertise required.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Kimberly Samra, a spokesperson for Google, which previously <a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/darksword-ios-exploit-chain\">analyzed the DarkSword exploit<\/a>, said the company\u2019s researchers agree with Frielingsdorf\u2019s assessment.\u00a0<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about Darksword, Coruna, or other government hacking and spyware tools? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2026\/03\/23\/someone-has-publicly-leaked-an-exploit-kit-that-can-hack-millions-of-iphones\/mailto:lorenzo@techcrunch.com\/\">by email<\/a><a href=\"https:\/\/techcrunch.com\/2026\/03\/23\/someone-has-publicly-leaked-an-exploit-kit-that-can-hack-millions-of-iphones\/mailto:lorenzo@techcrunch.com\/\">.<\/a> \t\t<\/div>\n<p class=\"wp-block-paragraph\">A security hobbyist who goes by the handle matteyeux also told TechCrunch that it is indeed trivial to use the leaked DarkSword samples. Matteyeux <a rel=\"nofollow\" href=\"https:\/\/x.com\/matteyeux\/status\/2035994616504226140\">wrote<\/a> in a post on X Monday that he was able to hack an iPad mini tablet running iOS 18, the previous generation of the operating system that is vulnerable to DarkSword, using the \u201cin the wild\u201d DarkSword sample that is circulating online.\u00a0<\/p>\n<div class=\"wp-block-techcrunch-inline-cta\">\n<div class=\"inline-cta__wrapper\">\n<p>Techcrunch event<\/p>\n<div class=\"inline-cta__content\">\n<p>\n\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__location\">San Francisco, CA<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__separator\">|<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__date\">October 13-15, 2026<\/span>\n\t\t\t\t\t\t\t<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"wp-block-paragraph\">Apple spokesperson Sarah O\u2019Rourke told TechCrunch that the company was aware of the exploit targeting devices running older and out-of-date operating systems, and issued an emergency update on March 11 for devices unable to run recent versions of iOS.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cKeeping your software up to date is the single most important thing you can do to maintain the security of your Apple products,\u201d O\u2019Rourke said, adding that devices with updated software were not at risk from these reported attacks, and that <a href=\"https:\/\/techcrunch.com\/2023\/12\/07\/apple-says-it-is-not-aware-anyone-using-lockdown-mode-got-hacked\/\">Lockdown Mode<\/a> would also block these specific attacks.<\/p>\n<p class=\"wp-block-paragraph\">A spokesperson for Microsoft, which owns GitHub, did not immediately respond to a request for comment.<\/p>\n<p class=\"wp-block-paragraph\">The code, which TechCrunch is not linking to as it can be used in active attacks, contains several comments that describe how the exploits work and how to implement them.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">One comment, likely written by one of the developers who worked on DarkSword, says that the exploit \u201creads and exfiltrates forensically-relevant files from iOS devices via HTTP,\u201d referring to stealing information from a person\u2019s iPhone or iPad and sending the data over the internet to an attacker-controlled server.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis payload should be injected into a process with filesystem access class,\u201d the comment reads.<\/p>\n<p class=\"wp-block-paragraph\">In one case, the code references \u201cpost-exploitation activity,\u201d and describes process after the malware has gained access to the person\u2019s phone and grabs its contents, including their contacts, messages, call history, and iOS keychain, which stores Wi-Fi passwords and other secrets, and dumps them into a remote server.<\/p>\n<p class=\"wp-block-paragraph\">Another file contains references to uploading data to a popular Ukrainian apparel website, though TechCrunch could not immediately determine why. DarkSword was <a href=\"https:\/\/techcrunch.com\/2026\/03\/18\/russians-caught-stealing-personal-data-from-ukrainians-with-new-advanced-iphone-hacking-tools\/\">allegedly used by Russian government<\/a> hackers against Ukrainian targets.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">This particular spyware works specifically against iPhones and iPads running iOS 18, according to iVerify, <a rel=\"nofollow\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/darksword-ios-exploit-chain\">Google<\/a>, and <a rel=\"nofollow\" href=\"https:\/\/www.lookout.com\/blog\/darksword\">Lookout<\/a>, which also previously analyzed the DarkSword malware.<\/p>\n<p class=\"wp-block-paragraph\"><a rel=\"nofollow\" href=\"https:\/\/developer.apple.com\/support\/app-store\/\">According to Apple\u2019s own numbers<\/a>, about one-quarter of all iPhone and iPad users are still running iOS 18 or earlier on their device. With <a rel=\"nofollow\" href=\"https:\/\/www.apple.com\/newsroom\/2026\/01\/apple-reports-first-quarter-results\/\">more than 2.5 billion<\/a> active devices, that likely equates to hundreds of millions of people whose devices are vulnerable to DarkSword attacks.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">That\u2019s why Frielingsdorf recommends everyone to upgrade their iPhone\u2019s operating system.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The discovery of DarkSword came only a few weeks after researchers discovered another advanced iPhone hacking toolkit <a href=\"https:\/\/techcrunch.com\/2026\/03\/03\/a-suite-of-government-hacking-tools-targeting-iphones-is-now-being-used-by-cybercriminals\/\">known as Coruna<\/a>. As TechCrunch reported, <a href=\"https:\/\/techcrunch.com\/2026\/03\/10\/us-military-contractor-likely-built-iphone-hacking-tools-used-by-russian-spies-in-ukraine\/\">Coruna was originally developed<\/a> by the defense contractor L3Harris, whose Trenchant division makes hacking tools for the U.S. government and its allies.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2026\/03\/23\/someone-has-publicly-leaked-an-exploit-kit-that-can-hack-millions-of-iphones\/\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week, cybersecurity resea&hellip; <\/p>\n","protected":false},"author":1,"featured_media":28549,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[249],"tags":[445,4437,1662,16180,459,3284,3210,1665,681,16179],"_links":{"self":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/28548"}],"collection":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=28548"}],"version-history":[{"count":0,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/posts\/28548\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=\/wp\/v2\/media\/28549"}],"wp:attachment":[{"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=28548"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=28548"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/microvibenews.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=28548"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}