DarkSword packs both a complete iOS exploit chain and infostealer into one package. The chain initiates when Safari opens a malicious webpage with a hidden iframe that springs the malware from the WebContent sandbox. It then works its way into deploying a number of custom payloads designed to tap into various vital and privileged iOS services.
A major threat actor has been crippled by an international law enforcement action, as the Lumma infostealer malware operation saw its control panel seized along with infrastructure dwelling in Europe and Japan. This was supplemented by Microsoft seizing some 2,300 domains belonging to the group, which has infected over 394,000 Windows computers globally.
Have I Been Pwned? (HIPB) has added 244 million freshly stolen passwords compromised via infostealer malware to an already existing list of 199 million, impacting 284 million unique user accounts.
A new report from cybersecurity firm Hudson Rock finds that infostealer malware is present on "thousands" of systems belonging to the US military and major defense contractors such as Boeing and Lockheed Martin.
Russian hackers stole 50 million passwords from popular online services such as PayPal, Amazon, Roblox, Steam and crypto wallets by deploying infostealer malware on users’ devices.





