VYPR
researchPublished Sep 30, 2026· 1 source

Russian Hackers Target Ukraine with Sophisticated Mobile Malware and iPhone Exploits

Ukrainian researchers have identified a surge in Russian-linked mobile malware campaigns, including the 'DarkSword' exploit kit specifically targeting iPhones, alongside new Android malware.

Ukrainian government researchers have issued a stark warning regarding an escalating campaign of Russian-linked mobile malware aimed at both iOS and Android devices, with a particular focus on compromising Ukrainian military and government personnel. The State Service of Special Communications and Information Protection (SSSCIP) highlighted the growing attractiveness of smartphones for espionage and financial attacks due to their central role in communications.

Central to this offensive is the 'DarkSword' exploit kit, a sophisticated tool designed to compromise iPhones. Attackers have employed watering-hole tactics, infecting legitimate websites that Ukrainian targets are likely to visit, including news and government portals. These attacks exploit vulnerabilities in Apple's Safari browser and iOS, capable of infecting iPhones with minimal user interaction. Once a device is compromised, sensitive data such as login credentials, messages, contacts, and call histories can be stolen.

DarkSword's deployment against Ukrainian users has been previously linked to suspected Russia-aligned hacking operations. Cybersecurity firm Lookout reported in March that a threat actor tracked as UNC6353 had been using DarkSword since at least late 2025, compromising sites like a regional news outlet and a local court. Unlike persistent spyware, DarkSword operates as a "hit-and-run" tool, rapidly extracting information and erasing its traces.

In addition to the iPhone exploits, Ukrainian authorities have identified two new hacking groups, UAC-0244 and UAC-0263, distributing malicious Android applications. These groups create deceptive websites impersonating Ukrainian entities or offering enticing services to lure users into downloading malware.

UAC-0244 has been observed distributing 'CamelSpy' malware through sites mimicking Ukraine’s 3rd Army Corps or offering services like a "men’s club." CamelSpy is capable of collecting device location, SIM card details, contacts, call logs, and stored images.

Meanwhile, UAC-0263 uses decoy websites for services such as air raid alerts or fuel discounts to distribute its 'BTMOB' malware. This malware grants attackers remote access to infected devices, enabling data theft.

These mobile-focused attacks are part of a broader cyber offensive against Ukraine. CERT-UA, Ukraine's national computer emergency response team, recorded a significant increase in cyber incidents during the first half of 2026, with a total of 3,137 incidents reported, an 8 percent rise compared to the previous six months.

The multi-platform approach, combining sophisticated iPhone exploits with deceptive Android applications, underscores the evolving and persistent nature of cyber threats targeting Ukraine, driven by state-sponsored actors.

Synthesized by Vypr AI