PULSE NAME
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
WHITE Unc6353 PetrP.73 2026-03-20 Modified: 2026-04-19
21
IOCs
MEDIUM VOLUME
The Google Threat Intelligence Group (GTIG) has identified a sophisticated exploit chain named DarkSword, specifically targeting iOS versions 18.4 to 18.7. This exploit encompasses multiple zero-day vulnerabilities, enabling full device compromise. DarkSword has been utilized by several threat actors, including commercial surveillance vendors and suspected state-sponsored groups, in various campaigns against targets across Saudi Arabia, Turkey, Malaysia, and Ukraine since late 2025. It has been observed that three malware families, GHOSTBLADE, GHOSTKNIFE, and GHOSTSABER, were deployed following successful infiltrations.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (21)
All CVE FileHash-SHA256 URL YARA domain hostname
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2025-14174 2026-03-20
CVE CVE-2025-31277 2026-03-20
CVE CVE-2025-43510 2026-03-20
CVE CVE-2025-43520 2026-03-20
CVE CVE-2025-43529 2026-03-20
CVE CVE-2026-20700 2026-03-20
FileHash-SHA256 2e5a56beb63f21d9347310412ae6efb29fd3db2d3a3fc0798865a29a3c578d35 2026-03-20
URL https://snapshare.chat/ 2026-03-20
URL https://static.cdncounter.net/assets/index.html 2026-03-20
URL https://static.cdncounter.net/widgets.js?uhfiu27fajf2948fjfefaa42 2026-03-20
YARA 0afa88a4dde47b4ad21dc1de87293814fc51499c 2026-03-20
YARA bac0e0ef16c3c657967bd2155ba6d8a6ef1df6a7 2026-03-20
YARA d2f1ea6229a205b693508c39f654dd8e3475763c 2026-03-20
YARA f4bc68581c02d6f390a8a56ff1c5d04e002afb39 2026-03-20
domain 0x1fedd2.open 2026-03-20
domain 0x436cc4.open 2026-03-20
domain sahibndn.io 2026-03-20
domain snapshare.chat 2026-03-20
hostname e5.malaymoil.com 2026-03-20
hostname sqwas.shapelie.com 2026-03-20
hostname static.cdncounter.net 2026-03-20