According to a post on Saturday by the Chief Information Security Officer of the blockchain security firm SlowMist regarding Darksword, it was reported that attackers are leveraging this malware to circumvent iOS security measures when a victim accesses an infected website;
the malware is set to activate on March 19, 2026 s posted by _act_ , to seize control of devices and extract private keys and other information from self-custodial Bitcoin wallets. The vulnerability is said to only impact iOS versions 18.4 to 18.7 then, but it now extends beyond the specified version. Here is what the Chief Information Security Officer of SlowMist said.
Unexpectedly, in one language, iOS users hurry to upgrade Black-gray industry has already achieved:
1. Clicking links to extract private keys and mnemonic phrases
2. Users access web pages via Safari, WebKit/JSC memory corruption to obtain JS layer read/write
3. Bypassing PAC to gain native call capabilities
4. Escaping the WebContent sandbox
5. Kernel privilege escalation to obtain root permissions, dragging away Keychain + wallet data
Affected versions iOS 13 to 26.5 (more versions pending)
https://x.com/im23pds/status/2101265052825428144?s=20