iPhone
Image: Tarun Raj BN via Unsplash

Mobile malware warning from Ukrainian researchers includes iPhone exploit kit

Russian hackers are increasingly targeting the smartphones of Ukrainian military personnel and government officials for espionage and financially motivated attacks, according to a Ukrainian government report published this week.

The hackers are going after both Android and iOS devices using malicious apps and sophisticated exploits, according to Ukraine’s State Service of Special Communications and Information Protection (SSSCIP).

“The growing role of smartphones in communications among military personnel, government employees and civilians makes them increasingly attractive targets for intelligence gathering, further compromise and financially motivated attacks,” researchers said.

One of the tools used against Ukrainian targets is DarkSword, an exploit kit designed to compromise iPhones.

DarkSword has been deployed in so-called watering-hole attacks, in which hackers compromise legitimate websites that their intended victims are likely to visit. In Ukraine, attackers have compromised news and government websites to exploit vulnerabilities in Apple’s Safari browser and iOS.

The technique can infect an iPhone with little or no action from the victim. Once the device is compromised, hackers can steal sensitive information, including login credentials, messages, contacts and call histories, according to SSSCIP.

Researchers have previously linked DarkSword activity targeting Ukraine to a suspected Russia-aligned hacking operation.

Cybersecurity firm Lookout reported in March that a threat actor it tracks as UNC6353 had used DarkSword against Ukrainian users since at least late 2025.

Lookout said the attackers compromised a regional news outlet covering the war and the website of a local court. Researchers also identified a possible infection at a Ukrainian food processing company.

Unlike spyware designed to remain on a phone and monitor its owner over a long period, DarkSword operates more like a “hit-and-run” operation. It can extract sensitive information within minutes and then remove traces of itself from the device, according to Lookout.

Ukrainian authorities have also tracked two relatively new hacking groups, known as UAC-0244 and UAC-0263, that distributed malicious Android apps through websites designed to lure Ukrainian users.

UAC-0244 has created sites impersonating Ukraine’s 3rd Army Corps and inviting visitors to “take a test,” as well as websites posing as a “men’s club” and other services.

The group distributed malware known as CamelSpy, which can collect information about an infected device, including its location, SIM cards, contacts and call logs, as well as images stored on the phone.

UAC-0263 has used decoy websites offering purported apps for air raid alerts, fuel discounts and other services. Its malware, known as BTMOB, gives hackers remote access to infected devices and allows them to steal information.

The mobile campaigns are part of a broader wave of cyber activity targeting Ukraine. CERT-UA, the country’s national computer emergency response team, recorded 3,137 cyber incidents during the first half of 2026 — about 8 percent more than during the previous six months.

Recorded Future
No previous article
No new articles
Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.