Observed Signal · Mar 24, 2026 · Exploit Leak · Source: t3n · Impact: 3/5 · Sentiment: Negative

Darksword Exploit Kit Leaked, Puts Millions of iPhones at Risk

Executive Signal Summary

A modified version of the Darksword exploit kit has been published publicly on GitHub, lowering the technical barrier for large-scale attacks against iPhones and iPads. Security researchers uncovered a related hacking campaign in mid‑March 2026 that could target hundreds of millions of devices still running older iOS versions. The leaked package is composed of HTML and JavaScript files and includes code comments explaining exploit behavior and data exfiltration. Apple says devices running the latest updates (iOS 26.4/iPadOS 26) are protected and has issued emergency fixes for older models; users are advised to update or enable Lockdown Mode for extra protection.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Public leak of a powerful exploit kit lowers attacker barriers and threatens devices at scale (potentially hundreds of millions). Apple updates mitigate risk for updated devices, but widespread unpatched devices raise security, privacy and fraud concerns across mobile ecosystems.

SIGNAL RADAR

Track Kit Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • A modified version of the Darksword exploit kit was published publicly on GitHub.
  • The leaked kit is composed mainly of HTML and JavaScript files, making it easy to copy, host and deploy.
  • Security researchers disclosed a hacking campaign in mid‑March 2026 targeting hundreds of millions of iPhones and iPads running older iOS versions.
  • Apple stated devices on the latest software (iOS 26.4 / iPadOS 26) are protected and provided emergency updates for older devices.
  • Code comments in the GitHub release describe how the exploits work and indicate attackers could exfiltrate data via attacker-controlled servers.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: Mar 24, 2026
Original Coverage Title: “Neue Darksword-Version geleakt: Warum dieses Exploit-Kit Millionen iPhones hacken kann | t3n”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

CybersecurityMar 23, 2026

DarkSword iPhone Exploit Kit Leaked on GitHub

Researchers say a newer version of DarkSword, an advanced iPhone exploit kit, was publicly uploaded to GitHub, enabling easy reuse by attackers. Security firms iVerify, Google and Lookout report the samples are simple HTML/JavaScript that can be copied and hosted quickly and successfully target devices running iOS 18 or earlier. A security hobbyist demonstrated a successful compromise of an iPad mini on iOS 18. Apple said it is aware of the exploit and issued an emergency update on March 11 for devices that cannot run newer iOS releases, and noted up-to-date devices and Lockdown Mode are not at risk. According to Apple numbers cited, about one-quarter of active iPhones and iPads run iOS 18 or earlier — out of more than 2.5 billion active devices — leaving potentially hundreds of millions vulnerable. DarkSword was previously linked to campaigns against Ukrainian targets; the discovery follows another toolkit called Coruna.

Read assessment
PrivacySep 29, 2026

Apple fixes iOS 26 zero-click security flaws

Apple has patched two critical security vulnerabilities affecting iOS 26, iPadOS 26, and macOS 26. The first, CVE-2026-86950, is a graphics engine bug that may have been exploited in highly sophisticated attacks. The second, CVE-2026-86869, is a zero-click iMessage vulnerability that could bypass BlastDoor, discovered by Belgian firm ironPeak and Meta. Apple credited Meta's product security team and ironPeak's Niels Hofmans. Both vulnerabilities affect a large user base still on iOS 26, though iOS 27 devices are unaffected. Details remain limited, and it's unknown if the flaws were actively exploited.

Read assessment
Security / Device VulnerabilityJun 22, 2026

Unpatchable Apple A12/A13 Boot ROM Flaw Enables Jailbreak

Paradigm Shift, an offensive cybersecurity company based in Barcelona that sells spyware and hacking tools to government agencies, published technical details and a proof-of-concept for a vulnerability it calls “usbliter8.” The flaw affects the Boot ROM on Apple A12 and A13 chips (used in iPhone XS, XR and iPhone 11), code burned into the chip that cannot be patched. Exploiting the bug requires physical access to the device (a cable connection) and could allow attackers or researchers to defeat boot-level security checks—potentially serving as a building block for iPhone jailbreaks when combined with other vulnerabilities. Paradigm Shift recommends migrating to newer hardware as the primary mitigation. The publication underscores that while modern iPhones are difficult to compromise, immutable low-level firmware bugs remain a persistent risk.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.