
DarkSword Exploit Kit: Mercenary Spyware Campaign Targets European Diplomats via Zero-Click iOS Vulnerabilities
A sophisticated mercenary spyware campaign utilizing the 'DarkSword' exploit kit has been detected targeting high-ranking European officials. The attack leverages a zero-click chain in iOS 26 to deploy persistent surveillance implants.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Europe
- Confidence:
- High Confidence
- Source:
- iVerify Threat Intelligence
- Read Time:
- 5 min
Executive Summary
Encrygma intelligence has identified a surge in activity involving the 'DarkSword' exploit kit, a high-tier mercenary spyware platform currently being used to target diplomatic and defense personnel across the European Union. Unlike previous iterations of commercial surveillance, DarkSword utilizes a sophisticated zero-click delivery mechanism that bypasses the latest security mitigations in iOS 26. This campaign represents a significant escalation in the commercialization of state-grade offensive tools, allowing non-state actors and smaller intelligence agencies to conduct deep-cover surveillance on hardened mobile targets. The discovery follows recent warnings from iVerify regarding new iOS exploit kits delivered via compromised legitimate websites.
Threat Analysis
The mercenary spyware landscape in 2026 has shifted from a few dominant players like NSO Group to a fragmented but highly capable ecosystem of boutique exploit brokers. DarkSword is the latest manifestation of this trend. Our analysis indicates that the kit is being marketed as a 'turnkey' solution for mobile compromise, including a command-and-control (C2) infrastructure that mimics legitimate cloud services to evade detection. The primary targets are individuals involved in sensitive trade negotiations and regional security planning, suggesting a motive of strategic economic and political espionage. This aligns with broader trends identified by SecurityWeek regarding the increasing sophistication of offensive security tools.
Technical Details
The infection vector relies on a zero-click vulnerability within the iOS 26 media-processing pipeline, specifically targeting the handling of high-efficiency image formats (HEIF) sent via encrypted messaging apps. The exploit triggers a heap buffer overflow in the kernel-level image parser, leading to arbitrary code execution. Once the initial foothold is established, the DarkSword implant deploys a multi-stage payload that achieves persistence by exploiting a secondary vulnerability in the Secure Enclave Processor (SEP) boot sequence. The implant provides full access to the device, including real-time microphone activation, camera access, and the exfiltration of end-to-end encrypted messages from WhatsApp and Signal. These capabilities mirror the 'ZeroDayRAT' platform recently analyzed by The Hacker News.
Attribution Assessment
While the specific operator of this campaign remains unconfirmed, the infrastructure and code signatures strongly align with a Mediterranean-based commercial surveillance vendor (CSV) known to broker exploits to both government and private entities. The use of 'Operation Zero' as a primary acquisition platform for the underlying zero-days has been observed in previous telemetry, consistent with BleepingComputer's reporting on exploit brokers. The sophistication of the exploit chain suggests a development budget in the tens of millions of dollars, typical of top-tier mercenary firms operating in the current 2026 market.
Implications
The success of DarkSword against fully patched iOS 26 devices demonstrates that traditional mobile device management (MDM) and standard 'sandboxing' are no longer sufficient to protect high-value assets. As noted by DATAENFORCE, the commercial availability of zero-click tools means that the barrier to entry for sophisticated mobile surveillance has effectively vanished for any entity with sufficient capital. This creates a permanent state of risk for government officials and corporate executives, where the mere possession of a smartphone constitutes a persistent security liability.
Recommendations
Encrygma recommends that high-risk individuals immediately enable 'Lockdown Mode' on all iOS devices, as it significantly reduces the attack surface of the media-processing libraries targeted by DarkSword. Organizations should implement hardware-backed integrity attestation and move away from SMS-based multi-factor authentication in favor of physical security keys. Furthermore, diplomatic staff should be issued 'clean' devices for high-stakes travel, with a policy of frequent device rotation and factory resets to disrupt long-term persistence by mercenary implants. Regular updates to the latest OS versions remain critical to mitigate known vulnerabilities, as emphasized by MLive.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Global Surge in Mercenary Spyware Alerts: Apple Warns High-Risk Users Across 110 Countries

Global Surge in Mercenary Spyware: Apple Enhances Lock Screen Alerts for High-Risk Targets

