TLDR Google researchers identified an Apple iOS exploit chain called DarkSword targeting unpatched iPhones. The exploit affects devices running iOS versions 18.TLDR Google researchers identified an Apple iOS exploit chain called DarkSword targeting unpatched iPhones. The exploit affects devices running iOS versions 18.

Google Flags Apple iOS Crypto Malware Targeting iPhones

2026/03/20 23:01
3 min di lettura
Per feedback o dubbi su questo contenuto, contattateci all'indirizzo crypto.news@mexc.com.

TLDR

  • Google researchers identified an Apple iOS exploit chain called DarkSword targeting unpatched iPhones.
  • The exploit affects devices running iOS versions 18.4 through 18.7.
  • Attackers use malicious or compromised websites to deploy the Ghostblade malware.
  • Ghostblade targets major crypto exchange and wallet applications on infected devices.
  • The malware collects messages, contacts, passwords, and crypto-related data before deleting itself.

Google researchers have identified a new exploit chain targeting Apple iOS devices. The chain deploys malware that focuses on cryptocurrency applications on unpatched iPhones. The researchers said attackers use the exploit in active campaigns across multiple regions.

Apple iOS Exploit Chain Delivers Ghostblade Malware

Google said the exploit chain, called DarkSword, affects devices running iOS 18.4 through 18.7. Researchers stated that the chain uses six vulnerabilities to gain access. They confirmed that attackers deploy the malware through malicious or compromised websites.

According to the report, the infection begins when a user visits a hostile website. The exploit then installs a JavaScript-based data stealer named Ghostblade. Google said, “Ghostblade focuses on rapid data collection before terminating itself.”

The malware searches for major crypto exchange apps on infected devices. It targets Coinbase, Binance, Kraken, Kucoin, OKX, and MEXC. It also scans for wallet apps such as Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe.

Ghostblade collects SMS and iMessage data from compromised phones. It also extracts call history, contacts, and saved Wi-Fi passwords. The malware retrieves Safari cookies, browsing history, and stored passwords.

Researchers reported that Ghostblade gathers Telegram and WhatsApp message history. It also captures location records, health data, and stored photos. After collecting data, the malware deletes temporary files and shuts down.

Google said multiple actors use the DarkSword exploit in the wild. These actors include commercial spyware vendors and state-backed groups. The company observed campaigns in Saudi Arabia and Ukraine.

Campaigns Target Crypto Users Across Regions

In Saudi Arabia, attackers distributed a fake Snapchat lookalike application. The application delivered the exploit to vulnerable devices. Google linked this campaign to actors seeking cryptocurrency-related information.

In Ukraine, attackers used compromised websites to spread the malware. One of the affected sites included a government domain. Google confirmed that the exploit activated when users accessed infected pages.

The researchers said Ghostblade focuses on fast data theft rather than surveillance. It collects available information and then removes traces. Google stated that the malware does not maintain persistent access.

The discovery follows recent crypto-focused malware incidents. Inferno Drainer stole about $9 million from crypto users over six months last year. Another campaign involved counterfeit Android smartphones pre-loaded with crypto-stealing malware.

Google urged users to update devices running vulnerable Apple iOS versions. The company said patched devices block the exploit chain. The findings mark the latest confirmed activity involving DarkSword and Ghostblade.

The post Google Flags Apple iOS Crypto Malware Targeting iPhones appeared first on Blockonomi.

Opportunità di mercato
Logo Major
Valore Major (MAJOR)
$0.06265
$0.06265$0.06265
+0.86%
USD
Grafico dei prezzi in tempo reale di Major (MAJOR)
Disclaimer: gli articoli ripubblicati su questo sito provengono da piattaforme pubbliche e sono forniti esclusivamente a scopo informativo. Non riflettono necessariamente le opinioni di MEXC. Tutti i diritti rimangono agli autori originali. Se ritieni che un contenuto violi i diritti di terze parti, contatta crypto.news@mexc.com per la rimozione. MEXC non fornisce alcuna garanzia in merito all'accuratezza, completezza o tempestività del contenuto e non è responsabile per eventuali azioni intraprese sulla base delle informazioni fornite. Il contenuto non costituisce consulenza finanziaria, legale o professionale di altro tipo, né deve essere considerato una raccomandazione o un'approvazione da parte di MEXC.

Potrebbe anche piacerti

Early CLARITY Act Deal Reached Between White House and US Lawmakers: Report

Early CLARITY Act Deal Reached Between White House and US Lawmakers: Report

The post Early CLARITY Act Deal Reached Between White House and US Lawmakers: Report appeared on BitcoinEthereumNews.com. Rumors are circulating that a tentative
Condividi
BitcoinEthereumNews2026/03/21 11:45
China Launches Cross-Border QR Code Payment Trial

China Launches Cross-Border QR Code Payment Trial

The post China Launches Cross-Border QR Code Payment Trial appeared on BitcoinEthereumNews.com. Key Points: Main event involves China initiating a cross-border QR code payment trial. Alipay and Ant International are key participants. Impact on financial security and regulatory focus on illicit finance. China’s central bank, led by Deputy Governor Lu Lei, initiated a trial of a unified cross-border QR code payment gateway with Alipay and Ant International as participants. This pilot addresses cross-border fund risks, aiming to enhance financial security amid rising money laundering through digital channels, despite muted crypto market reactions. China’s Cross-Border Payment Gateway Trial with Alipay The trial operation of a unified cross-border QR code payment gateway marks a milestone in China’s financial landscape. Prominent entities such as Alipay and Ant International are at the forefront, participating as the initial institutions in this venture. Lu Lei, Deputy Governor of the People’s Bank of China, highlighted the systemic risks posed by increased cross-border fund flows. Changes are expected in the dynamics of digital transactions, potentially enhancing transaction efficiency while tightening regulations around illicit finance. The initiative underscores China’s commitment to bolstering financial security amidst growing global fund movements. “The scale of cross-border fund flows is expanding, and the frequency is accelerating, providing opportunities for risks such as cross-border money laundering and terrorist financing. Some overseas illegal platforms transfer funds through channels such as virtual currencies and underground banks, creating a ‘resonance’ of risks at home and abroad, posing a challenge to China’s foreign exchange management and financial security.” — Lu Lei, Deputy Governor, People’s Bank of China Bitcoin and Impact of China’s Financial Initiatives Did you know? China’s latest initiative echoes the Payment Connect project of June 2025, furthering real-time cross-boundary remittances and expanding its influence on global financial systems. As of September 17, 2025, Bitcoin (BTC) stands at $115,748.72 with a market cap of $2.31 trillion, showing a 0.97%…
Condividi
BitcoinEthereumNews2025/09/18 05:28
XRPL Validator Reveals Why He Just Vetoed New Amendment

XRPL Validator Reveals Why He Just Vetoed New Amendment

Vet has explained that he has decided to veto the Token Escrow amendment to prevent breaking things
Condividi
Coinstats2025/09/18 00:28