INTEL_REPORT
Mandiant / Google Threat Intelligence Blog · published 3/18/2026, 2:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors Introduction Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG has observed multiple commercial surveillance vendors and suspected state-sponsored actors…
https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain
sha256:3687848b9a1b90ae43458909572deefaa0ba8373e3b8cc6b2c67799757f65219
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| document.createelement |
| Open → |
| domain | frame.src | Open → |
| domain | math.random | Open → |
| domain | frame.style.height | Open → |
| domain | frame.style.width | Open → |
| domain | frame.style.border | Open → |
| domain | document.body.appendchild | Open → |
| domain | top.location.href | Open → |
| domain | document.write | Open → |
| domain | console.log | Open → |
| domain | location.href | Open → |
| domain | xhr.open | Open → |
| domain | xhr.send | Open → |
| domain | xhr.responsetext | Open → |
| domain | url.createobjecturl | Open → |
| domain | date.now | Open → |
| domain | myhelper.getcontentsofdir | Open → |
| domain | file.includes | Open → |
| domain | com.apple.webkit | Open → |
| domain | myhelper.deletefileatpath | Open → |
| domain | window.location.href | Open → |
| domain | self.btoa | Open → |
| domain | json.stringify | Open → |
| domain | json.parse | Open → |
| domain | css.supports | Open → |
| domain | document.pictureinpictureenabled | Open → |
| domain | window.chrome | Open → |
| domain | 6297d177.html | Open → |
| domain | style.height | Open → |
| domain | style.width | Open → |
| domain | style.border | Open → |
| domain | static.cdncounter.net | Open → |
| domain | index.html | Open → |
| domain | iframe.src | Open → |
| domain | iframe.style.width | Open → |
| domain | iframe.style.height | Open → |
| domain | iframe.style.border | Open → |
| domain | iframe.style.position | Open → |
| domain | iframe.style.left | Open → |
| domain | iframe.style.opacity | Open → |
| domain | iframe.setattribute | Open → |
| domain | frame.style.opacity | Open → |
| domain | frame.style.position | Open → |
| domain | frame.style.left | Open → |
| domain | this.gettokenforpath | Open → |
| domain | systemgroup.com.apple.osanalytics | Open → |
| domain | ver.major | Open → |
| domain | ver.minor | Open → |
| domain | sahibndn.io | Open → |
| domain | e5.malaymoil.com | Open → |
| domain | sqwas.shapelie.com | Open → |
| domain | evaljsresponse.json | Open → |
| domain | com.apple | Open → |
| domain | metadata.plist | Open → |
| url | https://snapshare.chat/<redacted> | Open → |
| url | https://<redacted> | Open → |
| url | https://static.cdncounter.net/widgets.js?uhfiu27fajf2948fjfefaa42 | Open → |
| url | https://static.cdncounter.net/assets/index.html | Open → |
| sha256 | 2e5a56beb63f21d9347310412ae6efb29fd3db2d3a3fc0798865a29a3c578d35 | Open → |
| cve | CVE-2025-31277 | Open → |
| cve | CVE-2026-20700 | Open → |
| cve | CVE-2025-43529 | Open → |
| cve | CVE-2025-14174 | Open → |
| cve | CVE-2025-43510 | Open → |
| cve | CVE-2025-43520 | Open → |