- Google documented DarkSword deployments against targets in Saudi Arabia, Turkey, Malaysia and Ukraine from November 2025 onward. The cases involved distinct clusters and customers; they do not establish a worldwide victim total.
- iVerify’s estimate of up to 270 million devices on selected iOS 18 versions is a possible exposure denominator, not an infection count. Apple says current updated releases are protected and later extended fixes to older supported iOS branches.
Observed campaigns are smaller than the possible denominator
Google separated at least three operational contexts: UNC6748 used a Snapchat-themed site against Saudi users; activity associated with PARS Defense appeared in Turkey and later Malaysia; and UNC6353 used compromised Ukrainian websites as watering holes. UNC6353 is assessed as a suspected Russian espionage cluster, not a publicly proven arm of a named government.
The Ukrainian operation dated back to at least December 2025 and was active through March 2026. Lookout found evidence of one potential infection on 12 February. Neither finding supports the old claim that millions were attacked, and a compromised site does not show how many matching iPhones reached, completed or survived every exploit stage.
What the 270-million figure measures—and what it does not
iVerify said up to 270 million devices still ran iOS 18.4 through 18.6.2, versions supported by the Ukrainian DarkSword loader. It did not publish a measured count of relevant site visits, devices that received exploit code, successful privilege escalation, installed payloads or confirmed infections. The number is therefore an upper-bound population estimate, not an infection count.
Apple later reported that 79% of iPhones transacting on the App Store on 7 June used iOS 26. That percentage is newer and based on App Store activity; it is neither a total installed-base count nor a direct audit of DarkSword exposure. Combining the two denominators would create false precision.
Six flaws enabled different payloads
Google described a JavaScript chain spanning JavaScriptCore remote code execution, a dyld pointer-authentication bypass, two sandbox escapes and kernel privilege escalation. DarkSword supported iOS 18.4 through 18.7 across observed variants, while the Ukrainian UNC6353 loader supported 18.4 through 18.6.
Different campaigns delivered GHOSTKNIFE, GHOSTSABER or GHOSTBLADE. Their code could extract messages, accounts, browser and location history, Wi-Fi credentials, photos, files and app data. Those capabilities show severe impact after successful compromise; they do not prove that every module ran or every data type was stolen from every device.
The patch boundary moved after the disclosure
Google said the complete chain was fixed by iOS 26.3, released on 11 February 2026, although most flaws were patched earlier. Apple later said the latest updated versions of iOS 15 through iOS 26 were protected, expanded iOS 18.7.7 availability on 1 April and sent a Critical Security Update alert to older iOS 18 devices.
Apple says updated devices and devices with Lockdown Mode enabled were protected from the reported web attacks. Safari Safe Browsing blocks the identified domains. The operational response is still to install the latest supported update, use Lockdown Mode when updating is temporarily impossible, and investigate exposure rather than infer compromise from an OS version alone.
What to watch
- Confirmed victim telemetry separated from vulnerable-version estimates.
- New watering-hole domains, delivery code and Safe Browsing coverage.
- Exploit-stage success, payload execution and verified exfiltration evidence.
- New operators using DarkSword or modified components, with confidence levels.
- Patch adoption across managed and legacy iPhone fleets.
- Apple threat notifications and independent forensic findings.
Sources
- Google Threat Intelligence Group, 18 March 2026: campaigns, actors, exploit chain, payloads and patch chronology
- iVerify, 18 March 2026: Ukrainian watering-hole disclosure and the up-to-270-million version estimate
- Lookout, DarkSword analysis: delivery infrastructure, potential-infection observation and payload behavior
- Apple, iOS 26.3 security content: 11 February 2026 release and CVE-2026-20700 acknowledgement
- Apple, web-attack update guidance, 14 April 2026: legacy-iOS protection, Lockdown Mode, Safe Browsing and update advice
- Apple Developer, iOS usage measured 7 June 2026: App Store-transaction adoption denominator, not an infection measure

