Researchers at the Ukrainian Cyber Security Institute have warned that there are mobile malware campaigns targeting both Android and iOS devices, with attackers utilizing malicious applications and sophisticated exploit chains to target military personnel, government officials, and other individuals.
In a recent report released by the Ukrainian State Service of Special Communications and Information Protection (SSSCIP), the findings were highlighted, highlighting the increasing use of smartphones for communication and obtaining sensitive data.
An exploit kit designed for compromising iPhones was identified as one of the key tools identified in this activity, known as DarkSword.
During watering-hole attacks, the attackers compromised legitimate websites visited by the intended targets and modified them in order to deliver the attack. A number of Ukrainian news and government websites were targeted by attackers, enabling them to exploit vulnerabilities in Apple’s Safari browser and iOS.
As soon as an iPhone is compromised, DarkSword can be used to gather sensitive data such as login credentials, messages, contacts, and call histories without the victim having to interact significantly. In addition, earlier research has suggested that the activity may be linked to a Russian-led hacking operation targeting Ukrainians.
Researchers previously reported that the threat actor identified as UNC6353 used DarkSword against Ukrainian users from as late as late 2025. As part of the activity, compromised sites belonging to a local news outlet covering the war and a local court were compromised, and a possible infection was identified at a Ukrainian food processing facility.
DarkSword is described as an attack tool that is designed for a short period of time rather than a long-term solution.
This technique has been shown to be capable of extracting sensitive information within minutes and then erasing traces of the compromised device within minutes. Additionally, Ukrainian authorities are tracking activities associated with groups known as UAC-0244 and UAC-0263, which use websites that appear legitimate and encourage users to download applications. This campaign extends to Android devices as well.
To attract visitors, UAC-0244 created websites impersonating Ukraine's 3rd Army Corps and other services. One group, UAC-0263, distributed CamelSpy, an Android malware application capable of collecting information regarding device location, SIM card information, contacts, call logs, and stored images. It has been found that the BTMOB malware provides remote access to compromised devices and is capable of stealing information from them. It uses websites promoting supposed air raid alert applications, fuel discounts, and other services.
A number of these campaigns demonstrate how attackers use familiar online services to disguise malicious activity. Ukraine's SSSCIP reported that threat actors used platforms such as GitHub to host malicious files, Telegram for transferring stolen information, Cloudflare for concealment of part of their network activity and Ngrok for encrypting stolen data. Those mobile attacks are part of a wider cyber campaign targeting Ukraine.
CERT-UA reported 3,137 cyber incidents during the first half of 2026, representing an increase of approximately 8% from the preceding six-month period. There are still a number of security risks involved in mobile devices for Ukrainian citizens, with malicious websites, apps, and exploit tools being used to target iOS and Android devices.
