Threat intel
Ukraine report: Russian hackers turn to phones
Ukraine's cyber agency says DarkSword on iPhones and Android RATs behind fake military and air-raid apps were key tools in H1 2026. What to patch and block.
Ukraine's State Service of Special Communications and Information Protection (SSSCIP) published its "Cyber Threats: Ukraine" report for the first half of 2026 on September 30. One of its main findings is that attackers working for Russia are going after the smartphones of soldiers, officials and civilians, using the phones for reconnaissance and, when an attack lands, taking everything sensitive on them. On iPhones the tool is DarkSword, an exploit kit planted on hacked Ukrainian news and government websites. On Android it is spyware and remote access trojans (RATs) handed out through fake military unit pages and fake air-raid alert apps.
None of these tools is limited to Ukraine. Google has tied DarkSword to three separate groups, and BTMOB, one of the Android RATs in the report, is sold openly as malware-as-a-service. Any organisation with staff phones should read this as a list of what to check: iOS versions still below the fix, Android devices that allow apps from outside the store, and accessibility permissions nobody approved.
How DarkSword works on an iPhone
DarkSword is a full exploit chain written entirely in JavaScript, so the victim only has to open a web page in Safari. Google Threat Intelligence Group (GTIG) has watched it in use since November 2025 against iPhones running iOS 18.4 to 18.7. It chains six vulnerabilities, three of which were zero-days (unknown to Apple) when first used: CVE-2025-43529, CVE-2025-14174 and CVE-2026-20700.
The chain moves step by step out of the browser's sandbox, the restricted area where web content is supposed to stay. A bug in Safari's JavaScript engine, JavaScriptCore (CVE-2025-31277 on iOS 18.4, CVE-2025-43529 on 18.6 and 18.7), gives code execution inside the WebContent process, and CVE-2026-20700 in dyld defeats pointer authentication. A flaw in ANGLE, the graphics layer behind WebGL (CVE-2025-14174), breaks out into the GPU process. A kernel copy-on-write bug (CVE-2025-43510) moves on into the mediaplaybackd service, and a kernel race condition (CVE-2025-43520) finishes with full kernel privileges. Because every stage stays in JavaScript, the attackers never load a native binary, which avoids hardware-backed defences such as the Page Protection Layer (PPL) and Secure Page Table Monitor (SPTM) that are built to stop malicious native code.
What attackers are doing
GTIG attributes the Ukrainian campaign to UNC6353, a suspected Russian espionage group. Between December 2025 and March 2026 it added a script tag to compromised Ukrainian websites that pulled the first stage from static.cdncounter[.]net. The payload, GHOSTBLADE, is a data miner: it takes iMessage, WhatsApp and Telegram messages, call logs, contacts, keychain items, location history, saved Wi-Fi passwords, Safari cookies and cryptocurrency wallet data, and sends it to sqwas.shapelie[.]com. The SSSCIP describes it as hit and run, collecting within minutes and then removing itself, and GTIG notes it has no mode for running continuously. It also deletes crash reports from /private/var/containers/Shared/SystemGroup/systemgroup.com.apple.osanalytics/DiagnosticReports/, which removes one of the few traces an exploit leaves.
On Android the SSSCIP names two clusters. UAC-0244 builds sites that pose as Ukraine's 3rd Army Corps, inviting visitors to "take a test", and as a "men's club", and the download is CamelSpy, which collects device details, location, SIM card data, contacts, call logs and gallery images. UAC-0263 offers air-raid warning apps, fuel discounts and similar public services, and installs BTMOB.
BTMOB was first analysed by Cyble in January 2025 and grew out of an older RAT called SpySolr. After install it asks the user to switch on its accessibility service, an Android feature meant for assistive tools that can read the screen and tap buttons. Once that is granted, BTMOB gives itself its other permissions, streams the screen live over a WebSocket connection, logs keystrokes, captures the lock screen PIN or pattern, and loads phishing pages in a hidden WebView (an in-app browser) to collect logins as the victim types.
The agency also says the attackers hide behind services that look normal on a network: GitHub to host malicious files, Telegram to receive stolen data, and Cloudflare and ngrok to mask their servers. CERT-UA handled 3,137 incidents in the first half of 2026, about 8% more than the 2,909 in the second half of 2025.
What to do
1. Close DarkSword on every iPhone and iPad
Apple fixed the whole chain in iOS 26.3. For devices that stay on iOS 18, Apple took the unusual step on April 1, 2026 of offering iOS 18.7.7 to every iOS 18 device, from iPhone XR to iPhone 16e. In your mobile device management (MDM) inventory, flag anything below 26.3 that is not on 18.7.7. Better still, enforce the current builds: iOS 27 for devices that can run it, or iOS 26.7.1 from September 28, which also fixes the CoreGraphics flaw Apple says was exploited in targeted attacks on versions before iOS 27. On the device, the path is Settings > General > Software Update; models that can run iOS 26 list 18.7.7 under "Also Available".
For staff who travel to or work on Ukraine, journalists, and anyone else who could be a target for a state, turn on Lockdown Mode (Settings > Privacy & Security > Lockdown Mode). GTIG recommends it for devices that cannot update straight away. It disables the complex web features chains like this depend on, at the cost of some website breakage.
2. Shut the Android install path
Both Android families in the report arrive as APKs from websites, not from Google Play. On company-managed Android Enterprise devices, set the policy that blocks installs from unknown sources, and use the permitted accessibility services allowlist so only the assistive apps you approve can turn the feature on. Keep Google Play Protect enabled. On personal phones used for work, tell people plainly that real air-raid, banking and military apps come from the store and never from a link in a message.
3. Block and look for the infrastructure
Add cdncounter[.]net and shapelie[.]com to your DNS or secure web gateway blocklist, then search the past year of DNS and proxy logs for both. A hit from a phone means it reached the exploit server or sent data out. For Android, look for managed phones talking to api.telegram.org or ngrok tunnel domains where no approved app explains it.
4. Check devices you are unsure about
On Android, open Settings > Accessibility and Settings > Apps > Special app access > Install unknown apps, and question anything you do not recognise. An app holding accessibility rights that is not an assistive tool is a strong sign of a RAT. Remove it, then change the passwords and revoke the sessions of every account used on that phone, because BTMOB reads logins as they are typed.
On iPhones, a clean-looking device proves little: GHOSTBLADE leaves no persistent process and deletes its crash reports. If an at-risk user's iPhone ran iOS 18.4 to 18.7 and visited Ukrainian news or government sites between December 2025 and March 2026, assume its messages, keychain and Wi-Fi passwords may have been taken. Update it, then rotate the passwords, app sessions and Wi-Fi keys it held.
The wider lesson
Most patch reporting covers servers and laptops. Phones carry the same email, chat, MFA prompts and VPN profiles, yet their OS versions are often left to the user. Put mobile OS compliance in the same weekly report as endpoint patching, with a deadline, and give the MDM the power to block access from devices that miss it.
Our mobile penetration testing covers how your apps and device policies hold up against a hostile app on the same phone, and our security operations team can add mobile DNS and MDM signals to your monitoring. Open the chat and Yaali, our AI agent, will pass your question to an engineer.
Sources: The Record, Highload, UA.News, Mezha, Google Threat Intelligence Group, The Hacker News, Lookout, 9to5Mac, Bitdefender, Cyble, The Cyber Express.