Security1 publisher2 min readPublished
Ukraine's cyber agency ties DarkSword iPhone attacks to hacked news and government sites
Ukraine's SSSCIP says Russian hackers are going after military and government phones, using hacked news and government sites to push the DarkSword iPhone kit. Because the kit needs little or no action from the victim, the defense falls on the phone's own software and how current it is.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Lookout reported in March that a group it tracks as UNC6353 had used DarkSword against Ukrainian users since at least late 2025.
- Lookout found a regional war-news outlet and a local court's website compromised, plus a possible infection at a Ukrainian food processing company.
- On a compromised iPhone, SSSCIP says, the attackers can take login credentials, messages, contacts and call histories.
- Two relatively new groups, UAC-0244 and UAC-0263, spread malicious Android apps through websites built to lure Ukrainian users.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Examining a phone after a suspected visit to a compromised site will turn up little, since the kit is built to erase itself once the data is out.
- exposure Watering holes pick victims by readership, so civilians and firms that read a compromised war-news or court site are in range alongside soldiers and officials.
- constraint Awareness training fits the Android lures, where a victim has to install an app, and does little against an iPhone kit that fires on a page load.
- decision Units and ministries issuing iPhones have to decide how hard to force Safari and iOS updates, since those are the components the kit attacks.
Lookout describes DarkSword as a hit-and-run tool. It extracts sensitive information within minutes, then removes traces of itself from the device [11]. Lookout contrasted that with spyware designed to stay on a phone and monitor its owner over a long period [11]. The entry point is the browser. The compromised sites carry exploits for flaws in Safari and iOS [5].
SSSCIP's researchers tie the shift to where Ukrainian communications now run. "The growing role of smartphones in communications among military personnel, government employees and civilians makes them increasingly attractive targets for intelligence gathering, further compromise and financially motivated attacks," the researchers said [3].
The Record's account of the report does not identify the Safari and iOS flaws in the chain, or the iOS releases that fix them. The defensive read depends on that detail. If DarkSword uses flaws Apple has already patched, exposure on a given iPhone comes down to whether it runs current software, and a fleet that forces updates closes that entry. If the flaws are unpatched, a fully updated iPhone is still exposed, and the fix has to come from cleaning the compromised sites.
The Android side works through the victim. The report covers malicious apps on that platform alongside the iOS exploits [2]. UAC-0244 built sites impersonating Ukraine's 3rd Army Corps that invited visitors to "take a test," along with sites posing as a "men's club" [13]. Its CamelSpy malware collects location, SIM card details, contacts, call logs and stored images [13]. UAC-0263 ran decoy sites offering apps for air raid alerts and fuel discounts. Its BTMOB malware gives the operators remote access and lets them steal data [14].
DarkSword appeared in Lookout's March report and again in SSSCIP's report this week [2]. It has been in use against Ukraine for months and is still named in the newest government reporting.
Attribution stays at the level of suspicion. Researchers have linked the Ukraine activity to a suspected Russia-aligned operation [8], and UNC6353 is Lookout's tracking name for the group [9]. SSSCIP says the phone campaigns serve espionage and financially motivated attacks [1].
CERT-UA's first-half count puts the previous six months at roughly 2,900 incidents [1].
What to watch
- Publication of the specific Safari and iOS vulnerabilities in the DarkSword chain, and whether current iOS releases fix them.
- Evidence of DarkSword on compromised sites outside Ukraine, or aimed at audiences beyond Ukrainian users.
- CERT-UA's second-half 2026 incident count, and whether it breaks out mobile compromises.