Cybersecurity Today

Russian State Hackers Go After IoS Devices

Mar 30, 2026
Mac malware called Infinity Stealer uses social‑engineering to harvest browser credentials, Keychain items, crypto wallets and developer secrets. A leaked iOS exploit kit named DarkSword is being used in targeted phishing to deliver mobile implants while Apple issues unusual on‑device warnings. A kernel BPFdoor persists inside global telecom infrastructure. A PyPI supply‑chain compromise uses WAV steganography to exfiltrate secrets and target Kubernetes.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Compiled Python Malware Hits Mac Users

  • macOS is increasingly targeted using social-engineering click-fix pages that trick users into pasting Terminal commands.
  • Infinity Stealer is a Python payload compiled with Nuitka to a native binary that steals Keychain, browser creds, wallets, and dev secrets then notifies attackers via Telegram.
INSIGHT

DarkSword Turns iPhones Into Direct Targets

  • Russian FSB-aligned TA446 has shifted from credential phishing to using the DarkSword iOS exploit kit to deliver device-level malware.
  • DarkSword leaked on GitHub and Lookout warns it's simple enough for low-skilled actors, expanding the threat beyond nation-states.
ADVICE

Install iOS Updates Immediately When Warned

  • Update iPhones and iPads immediately when you see Apple's lock-screen warning about active web-based attacks.
  • Apple pushed unusual direct alerts for devices running older iOS versions, signaling a broad, active exploitation window.
Get the Snipd Podcast app to discover more snips from this episode
Get the app