DarkSword exploit compromises iOS 18.4-18.7 devices, targeting cryptocurrency wallets including Coinbase, Binance, and MetaMask. Update to iOS 26.3 now. The postDarkSword exploit compromises iOS 18.4-18.7 devices, targeting cryptocurrency wallets including Coinbase, Binance, and MetaMask. Update to iOS 26.3 now. The post

DarkSword Malware Strikes iOS: Crypto Wallets Under Attack

2026/03/20 21:02
3 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

Key Takeaways

  • DarkSword compromises iOS versions 18.4 through 18.7, exfiltrating cryptocurrency assets and sensitive information.
  • Ghostblade spyware focuses on popular exchanges like Coinbase, Binance, Kraken, and wallets such as Ledger and MetaMask.
  • Infection occurs through malicious websites requiring zero user interaction to compromise devices.
  • Malware payloads automatically erase themselves after successfully extracting victim data.
  • iOS 26.3 update addresses vulnerabilities; Lockdown Mode provides additional defense against DarkSword.

Cybersecurity researchers have uncovered DarkSword, a sophisticated exploit chain compromising Apple devices running iOS versions 18.4 to 18.7. This attack framework utilizes six previously unknown zero-day security flaws to deploy surveillance malware on targeted iPhones. Active campaigns have been detected across Saudi Arabia, Ukraine, Malaysia, and Turkey, indicating widespread deployment.

The DarkSword framework installs data-stealing malware capable of harvesting authentication credentials, communication records, and geolocation data. Cryptocurrency applications and digital wallets represent primary targets for this malicious campaign. Victims become infected simply by visiting weaponized web pages, requiring no clicks or downloads.

Security analysts have documented three distinct malware variants delivered via DarkSword: Ghostblade, Ghostknife, and Ghostsaber. These payloads rapidly extract targeted information before automatically removing themselves from infected systems. Evidence suggests both commercial surveillance companies and government-sponsored hacking groups are utilizing DarkSword in their operations.

Ghostblade Malware Hunts Cryptocurrency Applications

The Ghostblade payload distributed through DarkSword systematically scans compromised iOS devices for cryptocurrency exchange apps. Its target list encompasses leading trading platforms: Coinbase, Binance, Kraken, Kucoin, OKX, and MEXC. Additionally, it searches for prominent wallet software including Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe.

Beyond digital currency theft, Ghostblade harvests text messages, iMessages, phone logs, and contact lists from infected devices. The spyware extracts Wi-Fi passwords, Safari browser cookies, web history, and GPS coordinates. It further accesses Apple Health records, photo libraries, and conversations from messaging platforms like Telegram and WhatsApp.

Ghostblade executes a hit-and-run strategy, removing temporary artifacts and self-destructing after completing data exfiltration. This rapid execution minimizes forensic evidence left on compromised devices. The deployment of Ghostblade through DarkSword demonstrates escalating threats facing cryptocurrency holders.

Worldwide Campaign Distribution and Technical Operation

DarkSword deployment has been documented through weaponized websites and hijacked government web portals. Saudi Arabian victims were lured through a counterfeit Snapchat-themed page hosting the DarkSword exploit. The attack framework generates hidden iframes and retrieves remote code execution modules to inject malware payloads.

Various remote code execution exploits within DarkSword target distinct iOS versions, exploiting memory handling flaws and pointer authentication bypass weaknesses. The loader mechanism occasionally struggles with device version identification, suggesting accelerated development timelines. Nevertheless, DarkSword successfully delivers terminal payloads including Ghostknife and Ghostsaber across affected devices.

Security teams disclosed these vulnerabilities to Apple during late 2025, with remediation patches released in iOS 26.3. Domains associated with DarkSword distribution have been incorporated into browser Safe Browsing databases. iPhone owners should immediately install iOS updates or activate Lockdown Mode to defend against DarkSword exploitation.

DarkSword represents a critical security challenge for iOS cryptocurrency users worldwide. The exploit’s swift proliferation among diverse threat actors demonstrates heightened risks to digital financial holdings. Its comprehensive targeting of exchanges, wallets, and personal information emphasizes the urgency of applying available security patches.

The post DarkSword Malware Strikes iOS: Crypto Wallets Under Attack appeared first on Blockonomi.

Opportunità di mercato
Logo 4
Valore 4 (4)
$0.008926
$0.008926$0.008926
+12.60%
USD
Grafico dei prezzi in tempo reale di 4 (4)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment?

The post Is Doge Losing Steam As Traders Choose Pepeto For The Best Crypto Investment? appeared on BitcoinEthereumNews.com. Crypto News 17 September 2025 | 17:39 Is dogecoin really fading? As traders hunt the best crypto to buy now and weigh 2025 picks, Dogecoin (DOGE) still owns the meme coin spotlight, yet upside looks capped, today’s Dogecoin price prediction says as much. Attention is shifting to projects that blend culture with real on-chain tools. Buyers searching “best crypto to buy now” want shipped products, audits, and transparent tokenomics. That frames the true matchup: dogecoin vs. Pepeto. Enter Pepeto (PEPETO), an Ethereum-based memecoin with working rails: PepetoSwap, a zero-fee DEX, plus Pepeto Bridge for smooth cross-chain moves. By fusing story with tools people can use now, and speaking directly to crypto presale 2025 demand, Pepeto puts utility, clarity, and distribution in front. In a market where legacy meme coin leaders risk drifting on sentiment, Pepeto’s execution gives it a real seat in the “best crypto to buy now” debate. First, a quick look at why dogecoin may be losing altitude. Dogecoin Price Prediction: Is Doge Really Fading? Remember when dogecoin made crypto feel simple? In 2013, DOGE turned a meme into money and a loose forum into a movement. A decade on, the nonstop momentum has cooled; the backdrop is different, and the market is far more selective. With DOGE circling ~$0.268, the tape reads bearish-to-neutral for the next few weeks: hold the $0.26 shelf on daily closes and expect choppy range-trading toward $0.29–$0.30 where rallies keep stalling; lose $0.26 decisively and momentum often bleeds into $0.245 with risk of a deeper probe toward $0.22–$0.21; reclaim $0.30 on a clean daily close and the downside bias is likely neutralized, opening room for a squeeze into the low-$0.30s. Source: CoinMarketcap / TradingView Beyond the dogecoin price prediction, DOGE still centers on payments and lacks native smart contracts; ZK-proof verification is proposed,…
Condividi
BitcoinEthereumNews2025/09/18 00:14
Cardano Latest News, Pi Network Price Prediction and The Best Meme Coin To Buy In 2025

Cardano Latest News, Pi Network Price Prediction and The Best Meme Coin To Buy In 2025

The post Cardano Latest News, Pi Network Price Prediction and The Best Meme Coin To Buy In 2025 appeared on BitcoinEthereumNews.com. Pi Network is rearing its head, and Cardano is trying to recover from a downtrend. But the go to option this fall is Layer Brett, a meme coin with utility baked into it. $LBRETT’s presale is not only attractive, but is magnetic due to high rewards and the chance to make over 100x gains. Layer Brett Is Loading: Join or You’re Wrecked The crypto crowd loves to talk big numbers, but here’s one that’s impossible to ignore: Layer 2 markets are projected to process more than $10 trillion per year by 2027. That tidal wave is building right now — and Layer Brett is already carving out space to ride it. The presale price? A tiny $0.0058. That’s launchpad level, the kind of entry point that fuels 100x gains if momentum kicks in. Latecomers will scroll through charts in regret while early entrants pocket the spoils. Layer Brett is more than another Layer 2 solution. It’s crypto tech wrapped in meme energy, and that mix is lethal in the best way. Blazing-fast transactions, negligible fees, and staking rewards that could make traditional finance blush. Stakers lock in a staggering 700% APY. But every new wallet that joins cuts into that yield, so hesitation is expensive. And let’s not forget the kicker — a massive $1 million giveaway fueling even more hype around the presale. Combine that with a decentralized design, and you’ve got something that stands out in a space overcrowded with promises. This isn’t some slow-burning project hoping to survive. Layer Brett is engineered to explode. It’s raw, it’s loud, it’s built for the degens who understand that timing is everything. At $0.0058, you’re either in early — or you’re out forever. Is PI the People’s Currency? Pi Network’s open mainnet unlocks massive potential, with millions of users completing…
Condividi
BitcoinEthereumNews2025/09/18 06:14
How The ByteDance App Survived Trump And A US Ban

How The ByteDance App Survived Trump And A US Ban

The post How The ByteDance App Survived Trump And A US Ban appeared on BitcoinEthereumNews.com. WASHINGTON, DC – MARCH 13: Participants hold signs in support of TikTok outside the U.S. Capitol Building on March 13, 2024 in Washington, DC. (Photo by Anna Moneymaker/Getty Images) Getty Images From President Trump’s first ban attempt to a near-blackout earlier this year, TikTok’s five-year roller coaster ride looks like it’s finally slowing down now that Trump has unveiled a deal framework to keep the ByteDance app alive in the U.S. A look back at the saga around TikTok starting in 2020, however, shows just how close the app came to being shut out of the US – how it narrowly averted a ban and forced sale that found rare bipartisan backing in Washington. Recapping TikTok’s dramatic five-year battle When I interviewed Brendan Carr back in 2022, for example, the future FCC chairman was already certain at that point that TikTok’s days were numbered. For a litany of perceived sins — everything from the too-cozy relationship of the app’s parent company with China’s ruling regime to the app’s repeated floating of user privacy — Carr was already convinced, at least during his conversation with me, that: “The tide is going out on TikTok.” It was, in fact, one of the few issues that Washington lawmakers seemed to agree on. Even then-President Biden was on board, having resurrected Trump’s aborted TikTok ban from his first term and signed it into law. “It feels different now than it did two years ago at the end of the Trump administration, when concerns were first raised,” Carr told me then, in August of 2022. “I think, like a lot of things in the Trump era, people sort of picked sides on the issue based on the fact that it was Trump.” One thing led to another, though, and it looked like Carr was probably…
Condividi
BitcoinEthereumNews2025/09/18 07:29