Russia-linked hackers use advanced iPhone exploit to target Ukrainians

2026-03-19T02:51:54Zf89f4bc06f187ad44336bffe37db3fd5b2921ede3d860d65bca02d22732364ab
APTDarkSwordLookoutRussia-linkedUkraineanti-forensicsdata exfiltrationiOSiPhone exploitmobile malwaretargeted surveillancezero-click

What happened

Researchers at Lookout report a Russia-linked APT deploying an advanced iPhone exploit chain dubbed “DarkSword” to target Ukrainians. The malware reportedly achieves device compromise with little or no user interaction, can exfiltrate sensitive data within minutes, and remove traces of the intrusion. Details on the exploited iOS components or any assigned CVE were not reported in the article; the campaign represents targeted, high-risk mobile surveillance against activists, journalists, and officials.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
f89f4bc06f187ad44336bffe37db3fd5b2921ede3d860d65bca02d22732364ab
Enrichment time
2026-03-19T02:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.