Someone has publicly leaked an exploit kit that can hack millions of iPhones
Last week, cybersecurity researchers uncovered a hacking campaign targeting iPhone users that used an advanced hacking tool called DarkSword. Now someone has leaked a newer version of DarkSword and published it on the code-sharing site GitHub.
“I don’t think that can be contained anymore. So we need to expect criminals and others to start deploying this. ” Frielingsdorf said that these new versions of DarkSword spyware share the same infrastructure with the ones he and his iVerify colleagues analyzed previously, although the files are slightly different.
” “The exploits will work out of the box,” Frielingsdorf said.
“There is no iOS expertise required.
” Kimberly Samra, a spokesperson for Google, which previously analyzed the DarkSword exploit, said the company’s researchers agree with Frielingsdorf’s assessment.
A spokesperson for Microsoft, which owns GitHub, did not immediately respond to a request for comment.
One comment, likely written by one of the developers who worked on DarkSword, says that the exploit “reads and exfiltrates forensically-relevant files from iOS devices via HTTP,” referring to stealing information from a person’s iPhone or iPad and sending the data over the internet to an attacker-controlled server. “This payload should be injected into a process with filesystem access class,” the comment reads. In one case, the code references “post-exploitation activity” and describes process after the malware has gained access to the person’s phone and grabs its contents, including their contacts, messages, call history, and iOS keychain, which stores Wi-Fi passwords and other secrets, and dumps them into a remote server.
DarkSword was allegedly used by Russian government hackers against Ukrainian targets.
According to Apple’s own numbers, about one-quarter of all iPhone and iPad users are still running iOS 18 or earlier on their device.
That’s why Frielingsdorf recommends everyone upgrade their iPhone’s operating system
Logic Quality Breakdown:
- Updated_At:
- Truth_Blocks:
- Analysis_Method: