Millions of iPhones can be hacked with a new tool found in the wild

Summary: Researchers have discovered a sophisticated iPhone hacking technique called DarkSword, which can silently take over any iOS device running an older version of Apple’s operating system. The tool has been found on infected websites and is used by various cybercriminal groups.

Size
Standard

Links
Standard
Orange

* Subscribers only
Learn more

Espionage and cybercriminal campaigns have recently deployed iPhone hacking techniques, embedding them in infected websites to target thousands of iPhones. A particularly sophisticated technique, known as DarkSword, has been discovered by researchers at Google and cybersecurity firms iVerify and Lookout.

DarkSword is capable of silently taking over any iOS device running an older version of Apple’s operating system, including nearly a quarter of iPhones according to Apple's own data. The vulnerability lies in the fact that many users are still using outdated versions of the software. Researchers warn that hundreds of millions of iPhone users remain vulnerable.

The hacking campaign using DarkSword has been spotted by Google in Russian state-sponsored espionage groups and other hacker groups. However, it appears to have originated from different developers than another advanced hacking toolkit called Coruna. Both tools were embedded in legitimate Ukrainian websites, including news outlets and government agency sites, to harvest data.

In addition to the Russian spy campaign, DarkSword has also been used to compromise phones of victims in Saudi Arabia, Turkey, and Malaysia. The security firm PARS Defense appears to have employed this intrusion tool for some of their targets. This widespread use suggests that more hacking groups may adopt the technique due to its ease of deployment.

A concerning aspect is that the Russian hackers who recently used DarkSword left the full code on infected websites, complete with explanatory comments in English and the name.

Key facts

  • Researchers discovered a sophisticated iPhone hacking technique called DarkSword.
  • The tool can silently take over any iOS device running an older version of Apple’s operating system.
  • It has been found on infected websites and used by various cybercriminal groups.
  • Nearly a quarter of iPhones are still using outdated versions of the software, making them vulnerable.
  • DarkSword was left unobscured on some sites, inviting other hackers to reuse it.

Why it matters

The discovery of this new iPhone-hacking technique underscores the ongoing threat to mobile devices and highlights the importance of regular software updates. The ease with which attackers can reuse the technique puts a significant fraction of the world’s iPhone users at risk, potentially leading to data theft and other malicious activities.