DarkSword iOS exploit chain spread via ad networks for 11 weeks
Kaminari Ad exposed a malvertising campaign that delivered the DarkSword iOS exploit chain through ordinary programmatic ad inventory across 209 storefront domains and 337 cloaking-gate hosts over 11 weeks. The zero-click attack infected outdated iPhones, stole cryptocurrency wallet data and wiped the wallet apps, appearing in the traffic of roughly 15% of active accounts on the platform.
- 7,537 observations across 209 storefronts and 337 gate hosts over 11 weeks
- Zero-click attack: infection on page load, no ad tap required
- Payload targets crypto wallet data, then wipes the wallet apps
- Patched iPhones get a second exploit loader with no known CVE
Read next
Security