Threats · 10h ago
Ukraine's SSSCIP said this week that Russian actors are targeting Ukrainian military and government phones with malicious Android apps and the DarkSword iPhone exploit kit. The campaign uses watering-hole sites, so the victim gets hit by visiting a legitimate-looking page rather than by installing an obvious app.
On iPhone, DarkSword abuses Safari and iOS flaws through a compromised website; on Android, the lures deliver malicious apps from decoy sites. In both cases, the point is fast collection: once the phone is compromised, attackers can pull credentials, messages, contacts, and call history, then drop traces instead of staying resident.
For teams that rely on mobile devices for sensitive communications, the trust boundary is the browser as much as the app store. A site visit can now be enough to expose operational communications, even when no suspicious install ever happened.
1 source covering this story
The Record from Recorded Future
Mobile malware warning from Ukrainian researchers includes iPhone exploit kit
'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.
Part of the PlainSec briefing for 2026-09-30