New DarkSword tool targets hundreds of millions of iPhones

A hacking technique called DarkSword, used by Russian hackers, can compromise iPhones running iOS 18 simply by visiting infected websites. Discovered in the wild, this tool has been deployed in espionage and cybercriminal campaigns to target thousands of devices indiscriminately. It is now available online in a reusable form, risking a large portion of iPhone users worldwide.

iPhone hacking techniques were once rare, likened to elusive animals used stealthily against select targets. Recent developments show a shift, with espionage and cybercriminal groups embedding phone-takeover tools in websites to hack thousands of devices broadly. Among these is DarkSword, a powerful method spotted in active use by Russian hackers. This technique can seize control of devices on iOS 18 with just a visit to a malicious site, affecting hundreds of millions of iPhones. The tool has surfaced on the web in an easily adaptable format, heightening risks for many users. Previously selective hacks are now scaling up, as noted in cybersecurity observations.

Relaterede artikler

IT expert Supangat warns of Lebaran digital scams via WhatsApp and SMS in a press conference illustration.
Billede genereret af AI

IT expert warns of digital scams ahead of Lebaran

Rapporteret af AI Billede genereret af AI

Ahead of Idul Fitri, IT expert from Untag Surabaya, Supangat, urges the public to heighten vigilance against scams via WhatsApp and SMS. Rising digital transactions are exploited by cybercriminals. Vida founder Niki Santo Luhur identifies two main methods: phishing and malware prevalent in Indonesia.

Apple released an update to iOS 18.7.7 on April 1, 2026, making it available for more devices to protect against the DarkSword hacking toolkit. The company extended support to older iPhones, such as the iPhone 16e, without requiring an upgrade to iOS 26. DarkSword primarily targets users outside the US.

Rapporteret af AI

Kenyan entrepreneur Khalif Kairo has warned iPhone users who have lost their devices to beware of scammers using fake websites mimicking Apple. Fraudsters send SMS messages appearing to come from Apple Support, claiming the phone is in lost mode at a new location with a link. Kairo advised against entering Apple ID details on such links.

Hackers are targeting WhatsApp users with a new GhostPairing scam that allows full account access without cracking passwords or encryption safeguards. The scam bypasses traditional authentication methods, posing a significant risk to user privacy and security. Users are advised to check the Linked Devices section to detect any compromises.

Rapporteret af AI

A vulnerability in a popular WordPress quiz plugin has impacted over 40,000 sites, allowing potential SQL injection attacks. Security researchers have identified the flaw, urging site owners to check for exposure. The issue was reported on February 4, 2026.

Two groups linked to China are exploiting a newly discovered vulnerability in Cisco's email security products. The campaign involves zero-day attacks, highlighting ongoing cybersecurity risks. The issue was reported on December 19, 2025.

Rapporteret af AI

Hackers have accessed and stolen personal information from millions of Pornhub users, aiming to use the data for extortion schemes. The incident was highlighted in a WIRED security news roundup.

 

 

 

Dette websted bruger cookies

Vi bruger cookies til analyse for at forbedre vores side. Læs vores privatlivspolitik for mere information.
Afvis