TLDR DarkSword hits iOS 18.4–18.7, stealing crypto wallets and personal data. Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more. ExploitTLDR DarkSword hits iOS 18.4–18.7, stealing crypto wallets and personal data. Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more. Exploit

DarkSword Exploit Hits iOS Devices Targeting Crypto Users

2026/03/20 20:50
Okuma süresi: 3 dk
Bu içerikle ilgili geri bildirim veya endişeleriniz için lütfen crypto.news@mexc.com üzerinden bizimle iletişime geçin.

TLDR

  • DarkSword hits iOS 18.4–18.7, stealing crypto wallets and personal data.

  • Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more.

  • Exploit triggers via fake sites; no user action needed to infect devices.

  • Final-stage malware self-deletes after stealing sensitive data quickly.

  • Update to iOS 26.3 or enable Lockdown Mode to block DarkSword attacks.

A new iOS exploit chain called DarkSword is actively targeting devices running iOS 18.4 through 18.7. The exploit leverages six zero-day vulnerabilities to install malware on compromised devices. Multiple actors are deploying DarkSword against users in Saudi Arabia, Ukraine, Malaysia and Turkey.

DarkSword delivers malware designed to steal sensitive data, including login credentials, call history and location information. It specifically targets cryptocurrency apps and wallets on infected devices. Users visiting compromised websites can unknowingly trigger the exploit without any interaction.

Cybersecurity researchers have identified several final-stage malware families deployed through DarkSword. These include Ghostblade, Ghostknife, and Ghostsaber, which extract data quickly and self-delete afterward. The campaigns show DarkSword’s adoption by both commercial spyware vendors and state-backed threat actors.

Ghostblade Targets Crypto Exchanges and Wallets

Ghostblade, deployed by DarkSword, actively searches for cryptocurrency exchange applications on iOS devices. It targets major platforms such as Coinbase, Binance, Kraken, Kucoin, OKX, and MEXC. The malware also hunts popular wallets including Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe.

In addition to crypto assets, Ghostblade collects SMS, iMessage, call history, and contacts from the device. It also exfiltrates Wi-Fi credentials, Safari cookies, browsing history, and location information. The malware accesses health data, photos, and messaging history from Telegram and WhatsApp.

Ghostblade operates for short-term data theft, deleting temporary files and terminating itself after extraction. This quick-action design ensures minimal traces remain on the infected device. DarkSword’s ability to deliver Ghostblade highlights the increasing targeting of crypto users.

Global Deployment and Exploit Mechanics

DarkSword has been observed in targeted campaigns using fake websites and compromised government portals. In Saudi Arabia, a Snapchat-themed site was used to infect devices through DarkSword. The exploit chain creates iframes and fetches remote code execution modules to deliver the malware.

Different RCE exploits in DarkSword target specific iOS versions, including memory corruption and PAC bypass vulnerabilities. The loader logic sometimes fails to differentiate device versions, reflecting the tool’s rapid deployment. Despite this, DarkSword consistently installs final-stage payloads like Ghostknife and Ghostsaber.

Researchers reported the vulnerabilities to Apple in late 2025, and patches were included in iOS 26.3. Domains linked to DarkSword delivery are now added to Safe Browsing lists. Users are urged to update iOS devices or enable Lockdown Mode for added protection against DarkSword campaigns.

DarkSword has emerged as a significant threat to cryptocurrency users on iOS devices. The exploit’s rapid adoption by multiple actors signals a growing risk to digital assets. Its targeting of exchanges, wallets, and personal data underscores the need for immediate device updates.

The post DarkSword Exploit Hits iOS Devices Targeting Crypto Users appeared first on CoinCentral.

Piyasa Fırsatı
4 Logosu
4 Fiyatı(4)
$0.007681
$0.007681$0.007681
-0.73%
USD
4 (4) Canlı Fiyat Grafiği
Sorumluluk Reddi: Bu sitede yeniden yayınlanan makaleler, halka açık platformlardan alınmıştır ve yalnızca bilgilendirme amaçlıdır. MEXC'nin görüşlerini yansıtmayabilir. Tüm hakları telif sahiplerine aittir. Herhangi bir içeriğin üçüncü taraf haklarını ihlal ettiğini düşünüyorsanız, kaldırılması için lütfen crypto.news@mexc.com ile iletişime geçin. MEXC, içeriğin doğruluğu, eksiksizliği veya güncelliği konusunda hiçbir garanti vermez ve sağlanan bilgilere dayalı olarak alınan herhangi bir eylemden sorumlu değildir. İçerik, finansal, yasal veya diğer profesyonel tavsiye niteliğinde değildir ve MEXC tarafından bir tavsiye veya onay olarak değerlendirilmemelidir.

Ayrıca Şunları da Beğenebilirsiniz

Early CLARITY Act Deal Reached Between White House and US Lawmakers: Report

Early CLARITY Act Deal Reached Between White House and US Lawmakers: Report

The post Early CLARITY Act Deal Reached Between White House and US Lawmakers: Report appeared on BitcoinEthereumNews.com. Rumors are circulating that a tentative
Paylaş
BitcoinEthereumNews2026/03/21 11:45
China Launches Cross-Border QR Code Payment Trial

China Launches Cross-Border QR Code Payment Trial

The post China Launches Cross-Border QR Code Payment Trial appeared on BitcoinEthereumNews.com. Key Points: Main event involves China initiating a cross-border QR code payment trial. Alipay and Ant International are key participants. Impact on financial security and regulatory focus on illicit finance. China’s central bank, led by Deputy Governor Lu Lei, initiated a trial of a unified cross-border QR code payment gateway with Alipay and Ant International as participants. This pilot addresses cross-border fund risks, aiming to enhance financial security amid rising money laundering through digital channels, despite muted crypto market reactions. China’s Cross-Border Payment Gateway Trial with Alipay The trial operation of a unified cross-border QR code payment gateway marks a milestone in China’s financial landscape. Prominent entities such as Alipay and Ant International are at the forefront, participating as the initial institutions in this venture. Lu Lei, Deputy Governor of the People’s Bank of China, highlighted the systemic risks posed by increased cross-border fund flows. Changes are expected in the dynamics of digital transactions, potentially enhancing transaction efficiency while tightening regulations around illicit finance. The initiative underscores China’s commitment to bolstering financial security amidst growing global fund movements. “The scale of cross-border fund flows is expanding, and the frequency is accelerating, providing opportunities for risks such as cross-border money laundering and terrorist financing. Some overseas illegal platforms transfer funds through channels such as virtual currencies and underground banks, creating a ‘resonance’ of risks at home and abroad, posing a challenge to China’s foreign exchange management and financial security.” — Lu Lei, Deputy Governor, People’s Bank of China Bitcoin and Impact of China’s Financial Initiatives Did you know? China’s latest initiative echoes the Payment Connect project of June 2025, furthering real-time cross-boundary remittances and expanding its influence on global financial systems. As of September 17, 2025, Bitcoin (BTC) stands at $115,748.72 with a market cap of $2.31 trillion, showing a 0.97%…
Paylaş
BitcoinEthereumNews2025/09/18 05:28
XRPL Validator Reveals Why He Just Vetoed New Amendment

XRPL Validator Reveals Why He Just Vetoed New Amendment

Vet has explained that he has decided to veto the Token Escrow amendment to prevent breaking things
Paylaş
Coinstats2025/09/18 00:28