Second iOS exploit kit emerges from suspected Russian hackers using possible U.S. government-developed tools

2026-03-18T14:51:44Z3d55b57aa0fa061383b69d48dc44bc3292e479aeee61c68d22df13c26e5f68df
DarkSwordGoogle TAGLookoutRussian-linked actorsiOS exploit kitiVerifymobile exploitationmobile securityoffensive tooling reusezero-day/advanced exploits

What happened

CyberScoop reports researchers from iVerify, Lookout and Google have identified a second iOS exploit kit called “DarkSword” being used by suspected Russian-linked hackers. Analysis suggests the kit targets iOS devices and may reuse or be derived from exploit tooling developed for U.S. government offensive operations, raising concerns about leakage and repurposing of advanced mobile exploits and the broader implications for mobile security and attribution.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
3d55b57aa0fa061383b69d48dc44bc3292e479aeee61c68d22df13c26e5f68df
Enrichment time
2026-03-18T14:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.