Russia-linked hackers use advanced iPhone exploit to target Ukrainians
好的,我现在需要帮用户总结这篇文章的内容,控制在100个字以内。首先,我得通读整篇文章,抓住主要信息。 文章讲的是一个与俄罗斯有关的威胁行为者使用名为DarkSword的恶意软件攻击乌克兰用户,窃取敏感数据。这个恶意软件可以在用户几乎不进行任何操作的情况下入侵iPhone,并迅速提取数据后删除痕迹。攻击者主要通过“水坑”攻击,即感染乌克兰网站来传播病毒,比如新闻网站和法院网站。DarkSword的特点是快速收集数据然后删除自己,不像传统间谍软件那样长期监控。它还针对加密货币平台和钱包,显示出间谍和金融双重动机。苹果在2025年底修补了相关漏洞。 接下来,我需要把这些信息浓缩到100字以内,确保涵盖关键点:俄罗斯关联、DarkSword、iPhone入侵、乌克兰目标、数据窃取、水坑攻击、加密货币、苹果补丁。 可能的结构是:威胁行为者利用DarkSword攻击乌克兰iPhone用户,窃取敏感数据和加密货币信息,主要通过感染网站进行水坑攻击,苹果已修补漏洞。 检查字数是否在限制内,并确保语言简洁明了。 </think> 一个与俄罗斯相关的威胁行为者利用名为DarkSword的恶意软件攻击乌克兰iPhone用户,窃取敏感数据和加密货币信息。该恶意软件通过感染乌克兰网站进行“水坑”攻击,并在短时间内收集数据后删除痕迹。苹果已修补相关漏洞。 2026-3-18 20:2:48 Author: therecord.media(查看原文) 阅读量:6 收藏

A likely Russia-linked threat actor deployed a sophisticated iPhone hacking tool to target Ukrainian users and steal sensitive data, according to research published on Wednesday.

The malware, dubbed DarkSword, allows attackers to break into iPhones with little to no user interaction, extract sensitive data within minutes, and then erase traces of the intrusion, researchers at cybersecurity firm Lookout said.

They attributed the activity to a threat actor tracked as UNC6353. Little is known about the group’s infrastructure or broader affiliations, but it has previously targeted victims in Ukraine using the Coruna exploit chain.

The DarkSword campaign has been active since at least late 2025 and continued through March, primarily targeting visitors to compromised Ukrainian websites in so-called “watering hole” attacks, where hackers infect sites frequented by their intended victims.

Among the affected sites were a regional news outlet covering the war and a local court’s website. Researchers also identified a possible infection at a Ukrainian food processing company in February.

Once a victim visits an infected page, the attack is triggered automatically, allowing hackers to gain deep access to the device and retrieve emails, messages, photos, credentials and data from cryptocurrency wallets.

Unlike traditional spyware campaigns designed for long-term surveillance, DarkSword appears to operate on a “hit-and-run” model, according to Lookout. It rapidly collects and exfiltrates data, often within minutes, before deleting itself from the device.

“This malware is highly sophisticated and appears to be a professionally designed platform,” researchers said, noting that it was built to support modular development and long-term use.

The latest UNC6353 campaign combines espionage with financial motives, targeting a wide range of cryptocurrency platforms, including Coinbase, Binance and Kraken, as well as popular wallets such as MetaMask and Ledger.

Given the malware’s capabilities, researchers said the hackers may have access to high-end exploit tools typically associated with government clients or commercial surveillance vendors.

“The discoveries of DarkSword and previously Coruna suggest a secondary market for advanced exploits,” Lookout said, allowing actors with fewer resources to acquire and deploy sophisticated capabilities.

Despite the advanced tooling, the attackers themselves may not be highly sophisticated. Analysts noted limited efforts to conceal parts of the operation and suggested the group may rely on purchased exploits and even artificial intelligence to develop additional malware components.

According to a report by Google on Wednesday, DarkSword was deployed by various threat actors to target users in Saudi Arabia, Turkey and Malaysia.

Apple patched the vulnerabilities exploited in these attacks in late 2025 after they were disclosed, researchers said.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.


文章来源: https://therecord.media/russia-linked-hackers-use-iphone-exploit-ukraine
如有侵权请联系:admin#unsafe.sh