Information Warfare — 2026-10-03

Ukraine SSSCIP Warns Russian Hackers Deploying DarkSword iPhone Exploit and CamelSpy Against Military Personnel Smartphones

BLUFRussia's widening mobile exploitation toolkit against Ukrainian military smartphones will very likely yield additional publicly reported campaigns by year-end, driven by low infrastructure costs and expanding lure diversity.

Ukraine's SSSCIP reported this week that Russian-linked hackers are targeting Android and iOS smartphones of military personnel and government officials, according to The Record 1. The report describes DarkSword, an iPhone exploit kit delivered through compromised Ukrainian news and government websites that exploits Safari and iOS vulnerabilities and steals credentials, messages, contacts and call histories 12. The Record cited Lookout's March finding that UNC6353 had used DarkSword against Ukrainian users since at least late 2025 1. On Android, SSSCIP tracked UAC-0244, which spread CamelSpy through sites impersonating the 3rd Army Corps, and UAC-0263, which spread BTMOB through fake air raid alert and fuel discount apps 13. CERT-UA recorded 3,137 incidents in the first half of 2026, about 8 percent more than the prior six months 1.

Analysis
Ukraine's SSSCIP or CERT-UA will very likely publicly report at least one new Russian-attributed mobile malware or exploit campaign against military smartphones by year-end. Phones now carry troops' and officials' operational communications, lures keep widening, and attackers' use of GitHub, Telegram, Cloudflare and ngrok makes rotating infrastructure cheap. Rising CERT-UA incident counts sustain the reporting cadence. The surge in named campaigns may instead reflect expanded SSSCIP detection and disclosure rather than more Russian targeting, and some activity may be financially motivated criminal work rather than state-directed. Confidence is moderate because The Record is the only original reporting, the other outlets repeat it, and no independent technical confirmation of the attributions exists. If the judgment holds, commands and Western partners should tighten mobile device management, enforce iOS patching, and restrict sideloaded apps. A miss would weaken the case for diverting scarce defenses from other vectors.
4 sources
  1. Mobile malware warning from Ukrainian researchers includes iPhone exploit kit - The Record
  2. Hackers Used iOS and Android Phones to Scout Targets and Access Sensitive Data - Mezha.Media
  3. CERT-UA: понад 3000 кібератак РФ за пів року через ШІ - ЗНАЙ ЮА - ZNAJ.UA
  4. Mobile malware warning from Ukrainian researchers includes iPhone exploit kit - The Record

View in full brief →

UNCLASSIFIED // OPEN SOURCE