[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-154793-105":59,"doc-detail-154793-en":130},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":123,"head_meta":125,"extra_data":127,"updated_unix":129},105,"en","darksword-full-chain-ios-zeroday-exploitation-by-state-actors-multi-actor-deployment-of-a-six-vulnerability-iphone-exploit-kit","DarkSword - Full-Chain iOS ZeroDay Exploitation by State Actors - Multi-Actor Deployment of a Six-Vulnerability iPhone Exploit Kit","","DarkSword analyzes a full-chain iOS exploit kit disclosed in March 2026, which chains six vulnerabilities—including three zero-days—to compromise iPhones running specific iOS versions below 18.7.5 (and below iOS 26.3 on the iOS 26 branch). The attack is implemented in JavaScript within Safari, bypassing core iOS kernel integrity protections by defeating Pointer Authentication Codes (PAC) and TPRO. Reporting attributes deployment to multiple operators and highlights AI-assisted development lowering the barrier for advanced mobile exploitation, prompting immediate patching and behavioral monitoring recommendations.",{"@graph":69,"@context":122},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":40,"@type":76,"position":81},"https://docshare.wps.com/document/research-report/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/darksword-full-chain-ios-zeroday-exploitation-by-state-actors-multi-actor-deployment-of-a-six-vulnerability-iphone-exploit-kit/154793/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/darksword-full-chain-ios-zeroday-exploitation-by-state-actors-multi-actor-deployment-of-a-six-vulnerability-iphone-exploit-kit/154793.png","ImageObject",300,407,{"name":92,"@type":93},"Fahsai","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-09-30","2026-08-28",true,{"@type":102,"interactionType":103,"userInteractionCount":39},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118],{"name":109,"@type":110,"acceptedAnswer":111},"What is DarkSword and what does it accomplish on vulnerable iPhones?","Question",{"text":112,"@type":113},"DarkSword is a full-chain iOS exploit kit that chains six vulnerabilities, including three zero-days, to achieve complete device compromise on iPhones running vulnerable iOS versions below specified thresholds.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"How does the exploit execute without delivering a native binary?",{"text":117,"@type":113},"The entire attack is implemented in JavaScript and runs inside Safari’s browser engine, enabling execution without requiring native binary delivery.",{"name":119,"@type":110,"acceptedAnswer":120},"Why is the attack considered more dangerous than a single-actor campaign?",{"text":121,"@type":113},"The disclosure attributes deployment to multiple independent operators, increasing the likelihood of sustained, evolving targeting rather than a one-time operation.","https://schema.org",{"og:url":83,"og:type":124,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":126,"canonical":83},"index,follow",{"doc_id":128,"site_id":62},154793,1787899086,{"code":4,"msg":5,"data":131},{"doc_id":128,"user_id":132,"nickname":92,"user_avatar":133,"doc_module":4,"category_id":39,"category_name":40,"doc_title":65,"doc_description":67,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":39,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":139,"language":140,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":67,"update_tm":129,"read_time":144},549768702563,"https://ap-avatar.wpscdn.com/avatar/8000c4aa63b76e948b?x-image-process=image/resize,m_fixed,w_180,h_180&k=1786536092046926083","DarkSword: Full-Chain iOS ZeroDay Exploitation by State Actors  \nMulti-Actor Deployment of a Six-Vulnerability iPhone Exploit Kit  \nUnofficial AI-assisted Research  \nCloud Security Alliance AI Safety Initiative  \n2026-03-19  \n© 2026 Cloud Security Alliance. Unofficial AI-assisted Research. 1  \n© 2026 Cloud Security Alliance. Some rights reserved.  \nYou may download, store, display, view, print, redistribute, and link to this document in its original, unmodified form, provided that attribution to the Cloud Security Alliance is maintained and all trademark and copyright notices remain intact.  \nThis document may not be modified or altered. You may quote portions of the document as permitted by the Fair Use provisions of the United States Copyright Act, provided that attribution is given to the Cloud Security Alliance.  \nThis document may be shared on professional and social media platforms in its original form with attribution.  \nThis document was generated with AI assistance and has not undergone official CSA review and approval processes.  \n© 2026 Cloud Security Alliance. Unofficial AI-assisted Research. 2  \nKey Takeaways  \nOn March 18, 2026, Google Threat Intelligence Group (GTIG), iVerify, and Lookout jointly disclosed DarkSword, a full-chain iOS exploit kit that chains six vulnerabilities — three of them zero-days — to achieve complete device compromise on iPhones running iOS versions below 18.7.5 (and below iOS 26.3 on the iOS 26 branch) [1][2][3] . The entire attack is implemented in JavaScript, executing within Safari's browser engine without requiring any native binary delivery, and successfully bypasses Apple's Pointer Authentication Codes (PAC) and Trusted Page Reference Owner (TPRO) protection — two of Apple's primary kernel integrity controls [4] . SiliconANGLE reported that iVerify estimated up to 270 million iPhones remained on vulnerable iOS versions at the time of public disclosure [5] .  \nDarkSword is not a single-actor campaign. GTIG attributed the kit's deployment to at least three independent operators: UNC6353, a suspected Russian espionage group targeting Ukrainian civilians via watering hole attacks; UNC6748, an unattributed state or state-adjacent actor targeting Saudi Arabian users via social engineering; and PARS Defense, a Turkish commercial surveillance vendor with documented deployments in Turkey and Malaysia [1][6] . The kit's server-side components contained an unobfuscated artifact labeled \" Dark sword file receiver\" — from which the kit takes its public name [4] . Multiple reporting outlets additionally note that large language models were used to assist in customizing both DarkSword and its predecessor Coruna, underscoring how AI-assisted development is lowering the technical barrier for advanced mobile exploit construction [7] .  \nThe disclosures arrive as the commercial surveillance vendor ecosystem — encompassing Paragon Solutions, Intellexa, and the recently litigated NSO Group — faces mounting regulatory and legal pressure, even as exploit reuse between commercial products and state APT groups becomes a documented structural feature of the iOS threat landscape [8][9][10] . Organizations responsible for the protection of journalists, activists, executives, lawyers, and other high-risk iPhone users must treat DarkSword as evidence of an enduring and evolving threat requiring immediate patching, behavioral monitoring, and the systematic use of Apple's Lockdown Mode for exposed populations.  \n© 2026 Cloud Security Alliance. Unofficial AI-assisted Research. 3  \nBackground  \nThe iOS Zero-Day Landscape Entering 2026  \nApple's iOS has long been among the most actively exploited operating systems in the mercenary spyware ecosystem, not despite its security architecture but, in part, because of it: the platform's ubiquity among high-value targets, its closed software distribution model, and the reliability of its process isolation make a successful iOS exploit extraordinarily valuable to both state ","cbCaikweElJF0M8B","https://ap.wps.com/l/cbCaikweElJF0M8B","pdf",322331,13,"English","# Key Takeaways\n## iOS full-chain exploit kit details\n## Multi-actor deployment and AI assistance\n# Background\n## The iOS Zero-Day landscape entering 2026\n## CVE-2026-20700: The anchor zero-day","[{\"question\":\"What is DarkSword and what does it accomplish on vulnerable iPhones?\",\"answer\":\"DarkSword is a full-chain iOS exploit kit that chains six vulnerabilities, including three zero-days, to achieve complete device compromise on iPhones running vulnerable iOS versions below specified thresholds.\"},{\"question\":\"How does the exploit execute without delivering a native binary?\",\"answer\":\"The entire attack is implemented in JavaScript and runs inside Safari’s browser engine, enabling execution without requiring native binary delivery.\"},{\"question\":\"Why is the attack considered more dangerous than a single-actor campaign?\",\"answer\":\"The disclosure attributes deployment to multiple independent operators, increasing the likelihood of sustained, evolving targeting rather than a one-time operation.\"}]","DarkSword - Full-Chain iOS ZeroDay Exploitation by State Actors - Multi-Actor Deployment of a Six-Vulnerability iPhone Exploit Kit | PDF",33]