TLDR DarkSword hits iOS 18.4–18.7, stealing crypto wallets and personal data. Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more. ExploitTLDR DarkSword hits iOS 18.4–18.7, stealing crypto wallets and personal data. Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more. Exploit

DarkSword Exploit Hits iOS Devices Targeting Crypto Users

2026/03/20 20:50
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • DarkSword hits iOS 18.4–18.7, stealing crypto wallets and personal data.

  • Ghostblade malware targets Coinbase, Binance, Ledger, MetaMask, and more.

  • Exploit triggers via fake sites; no user action needed to infect devices.

  • Final-stage malware self-deletes after stealing sensitive data quickly.

  • Update to iOS 26.3 or enable Lockdown Mode to block DarkSword attacks.

A new iOS exploit chain called DarkSword is actively targeting devices running iOS 18.4 through 18.7. The exploit leverages six zero-day vulnerabilities to install malware on compromised devices. Multiple actors are deploying DarkSword against users in Saudi Arabia, Ukraine, Malaysia and Turkey.

DarkSword delivers malware designed to steal sensitive data, including login credentials, call history and location information. It specifically targets cryptocurrency apps and wallets on infected devices. Users visiting compromised websites can unknowingly trigger the exploit without any interaction.

Cybersecurity researchers have identified several final-stage malware families deployed through DarkSword. These include Ghostblade, Ghostknife, and Ghostsaber, which extract data quickly and self-delete afterward. The campaigns show DarkSword’s adoption by both commercial spyware vendors and state-backed threat actors.

Ghostblade Targets Crypto Exchanges and Wallets

Ghostblade, deployed by DarkSword, actively searches for cryptocurrency exchange applications on iOS devices. It targets major platforms such as Coinbase, Binance, Kraken, Kucoin, OKX, and MEXC. The malware also hunts popular wallets including Ledger, Trezor, MetaMask, Exodus, Uniswap, Phantom, and Gnosis Safe.

In addition to crypto assets, Ghostblade collects SMS, iMessage, call history, and contacts from the device. It also exfiltrates Wi-Fi credentials, Safari cookies, browsing history, and location information. The malware accesses health data, photos, and messaging history from Telegram and WhatsApp.

Ghostblade operates for short-term data theft, deleting temporary files and terminating itself after extraction. This quick-action design ensures minimal traces remain on the infected device. DarkSword’s ability to deliver Ghostblade highlights the increasing targeting of crypto users.

Global Deployment and Exploit Mechanics

DarkSword has been observed in targeted campaigns using fake websites and compromised government portals. In Saudi Arabia, a Snapchat-themed site was used to infect devices through DarkSword. The exploit chain creates iframes and fetches remote code execution modules to deliver the malware.

Different RCE exploits in DarkSword target specific iOS versions, including memory corruption and PAC bypass vulnerabilities. The loader logic sometimes fails to differentiate device versions, reflecting the tool’s rapid deployment. Despite this, DarkSword consistently installs final-stage payloads like Ghostknife and Ghostsaber.

Researchers reported the vulnerabilities to Apple in late 2025, and patches were included in iOS 26.3. Domains linked to DarkSword delivery are now added to Safe Browsing lists. Users are urged to update iOS devices or enable Lockdown Mode for added protection against DarkSword campaigns.

DarkSword has emerged as a significant threat to cryptocurrency users on iOS devices. The exploit’s rapid adoption by multiple actors signals a growing risk to digital assets. Its targeting of exchanges, wallets, and personal data underscores the need for immediate device updates.

The post DarkSword Exploit Hits iOS Devices Targeting Crypto Users appeared first on CoinCentral.

Market Opportunity
4 Logo
4 Price(4)
$0.00765
$0.00765$0.00765
+0.52%
USD
4 (4) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Tags:

You May Also Like

UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future

UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future

The post UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future appeared on BitcoinEthereumNews.com. Key Highlights Microsoft and Google pledge billions as part of UK US tech partnership Nvidia to deploy 120,000 GPUs with British firm Nscale in Project Stargate Deal positions UK as an innovation hub rivaling global tech powers UK and US Seal $42 Billion Tech Pact Driving AI and Energy Future The UK and the US have signed a “Technological Prosperity Agreement” that paves the way for joint projects in artificial intelligence, quantum computing, and nuclear energy, according to Reuters. Donald Trump and King Charles review the guard of honour at Windsor Castle, 17 September 2025. Image: Kirsty Wigglesworth/Reuters The agreement was unveiled ahead of U.S. President Donald Trump’s second state visit to the UK, marking a historic moment in transatlantic technology cooperation. Billions Flow Into the UK Tech Sector As part of the deal, major American corporations pledged to invest $42 billion in the UK. Microsoft leads with a $30 billion investment to expand cloud and AI infrastructure, including the construction of a new supercomputer in Loughton. Nvidia will deploy 120,000 GPUs, including up to 60,000 Grace Blackwell Ultra chips—in partnership with the British company Nscale as part of Project Stargate. Google is contributing $6.8 billion to build a data center in Waltham Cross and expand DeepMind research. Other companies are joining as well. CoreWeave announced a $3.4 billion investment in data centers, while Salesforce, Scale AI, BlackRock, Oracle, and AWS confirmed additional investments ranging from hundreds of millions to several billion dollars. UK Positions Itself as a Global Innovation Hub British Prime Minister Keir Starmer said the deal could impact millions of lives across the Atlantic. He stressed that the UK aims to position itself as an investment hub with lighter regulations than the European Union. Nvidia spokesman David Hogan noted the significance of the agreement, saying it would…
Share
BitcoinEthereumNews2025/09/18 02:22
Shiba Inu (SHIB) Sees Shorts Exit in 4 Hours While Price Eyes Recovery

Shiba Inu (SHIB) Sees Shorts Exit in 4 Hours While Price Eyes Recovery

The post Shiba Inu (SHIB) Sees Shorts Exit in 4 Hours While Price Eyes Recovery appeared on BitcoinEthereumNews.com. Shiba Inu reversed a three-day drop earlier
Share
BitcoinEthereumNews2026/03/22 16:25
Szabo Warns Developers Not to Break Bitcoin

Szabo Warns Developers Not to Break Bitcoin

The post Szabo Warns Developers Not to Break Bitcoin appeared on BitcoinEthereumNews.com. The nonviolent blockchain Is Bitcoin used as money?  Legendary cryptographer
Share
BitcoinEthereumNews2026/03/22 16:37