A new report from Google reveals a sophisticated attack chain designed to install malware and steal cryptocurrency from iPhone devices. The Threat Analysis Group (TAG) detailed how the operation called DarkSword chains six critical vulnerabilities to compromise iOS versions between 18.4 and 18.7, using infected websites as the main intrusion vector.
The attack is deployed using «watering-hole» techniques (also known as watering hole attacks). These are targeted and selective cyber attack strategies. Its name comes from the analogy with nature in which a predator lurks in a watering hole where animals go to drink water, waiting for the right moment to strike when prey is distracted or vulnerable. In cybersecurity, the “watering hole” is a legitimate or trusted website that a specific group of users visits frequently.
In such a way that, when visiting their favorite sites, the user is infected. Once system defenses are overcome, the exploit installs one of three families of malware. These are GHOSTBLADE, GHOSTKNIFE or GHOSTSABER. Among them stands out GHOSTBLADE, a JavaScript-based infostealer that extracts from Safari histories and Telegram messages, even access keys to bitcoin and cryptocurrencies in applications such as MetaMask, Ledger, Phantom and Binance.
The technical sophistication of this threat lies in its ability to compromise structural components such as the JavaScriptCore engine and the iOS kernel. The researchers identified that Attackers exploited zero-day flaws before official patches existed.

On its official blog, Google’s intelligence unit was blunt in describing DarkSword as a «full exploit chain that uses six different vulnerabilities to deploy final payloads.»
The Russian spy group UNC6353 has been linked to targeted attacks in Ukraine, while other incidents affected users in Saudi Arabia and Türkiye. This pattern reinforces the critical trend regarding the use of this type of malware to steal cryptocurrencies and obtain strategic information through commercial surveillance tools.
Apple says it has completed the fix for these bugs with the update to iOS 26.3, urging users to keep their devices up to date. However, it is clear that as long as smartphones centralize our financial and private lives, malicious code will continue to look for cracks in the system. In this environment, updating immediately is the only way to ensure that our digital identity and funds remain safe.
Incidentally, Ledger CTO Charles Guillemet expressed concern about this new wave of sophisticated attacks: “State-grade iOS exploits do not stay in the hands of the government. They filter, spread, and end up in broader ecosystems. “One visit to a compromised site and your phone, including your cryptocurrencies, is gone.” He added: «From now on, you should assume that your phone is compromised. Stop treating it like a safe.
The Binance team also issued a warning about the risk posed by this new form of hacking: “The exploit can be activated automatically without any user interaction, allowing attackers to extract sensitive data, including information from cryptocurrency wallets. “Malware can also erase its traces after execution.”
The trail left by DarkSword is actually the latest chapter in a systematic offensive against mobile security. Just a few weeks earlier, at the beginning of March 2026, as reported by NoticiasVE, the Coruna exploit kit had already exposed the seams of self-custody in iOS versions ranging from 13 to 17.2.1.
That system, also detected by Google’s intelligence team, operated under the same premise of deep intrusion. That’s digging through notes, photos, and local files to extract recovery phrases from wallets like MetaMask, Trust Wallet, and Exodus.
This recurrence of critical vulnerabilities reveals a persistent crack in Apple’s architecture that attackers are exploiting with surgeon-like precision. In an environment where state espionage tools are rapidly mutating toward direct financial theft, Immediate software updating stops being advice and becomes an act of digital survival. If the code does not rest in its attempt to violate privacy, the defense of our financial sovereignty cannot afford a pause either.