Abandoned iphones become open vaults as darksword exploit hits github
A weaponized exploit kit that can pry open every file on a vintage iPhone is now one click away on GitHub. DarkSword, the same chain Google’s Threat Analysis Group quietly flagged to Apple in mid-March, surfaced in public repositories late last week, turning forgotten handsets into silent informants.
The clock started months ago
Google’s researchers first spotted the payload circulating against iOS 18.6.2 and older, but kept the technical write-up under seal while Apple patched. That embargo snapped when an anonymous account pushed a working fork to Microsoft-owned GitHub. Within hours, hobbyists on X posted kernel read/write screenshots from an iPad mini 6 still running 18.6.2. The message: if the device boots, it leaks.
Matthias Frielingsdorf, co-founder of the mobile-security startup iVerify, watched the repository star counter climb past 1 400 before breakfast. “We logged 500 000 requests for the zipball in 48 hours,” he told me from Berlin. “Script kiddies, forensic contractors, bored teenagers—everyone grabbed it.” His team’s telemetry shows the majority of probes hitting IP ranges tied to second-hand iPhones 7 and 8, models that rarely see updates anymore.

Why stale phones never die
Apple’s statistics paint a rosy picture: 89 % of active iPhones run iOS 18. But the company stops counting hardware it no longer signs. That orphan cohort—roughly 180 million units by Frielingsdorf’s estimate—still powers parking meters, hospital tablets, kids’ gaming rigs. DarkSword doesn’t jailbreak them; it simply asks politely for every photo, chat database and keychain via a malformed HTTP request. No user tap required.
The kit bundles three zero-days: a WebKit type confusion, a kernel privilege scaler and a sandbox escape last patched in March. Apple back-ported the fixes only to iOS 17 and 18. Anything frozen on 16 or earlier remains naked. “It’s a Swiss-army knife with the blades already open,” Frielingsdorf said. “You just hand it to the victim device.”

Github becomes the malware bazaar
Microsoft, which owns the code-hosting platform, declined to comment on why the repo remains live. GitHub’s policy allows security research, yet the same account that uploaded DarkSword seeded 40 cryptocurrency-mining commits laced with info-stealers last month. The contradiction is not lost on defenders. “GitHub is turning into the new Discord for malware distribution,” a senior Apple engineer vented on an internal Slack channel I was shown. “We file takedowns, they re-upload under a new hash. Whac-A-Mole at planetary scale.”
Meanwhile, generative-AI coding assistants are lowering the bar. Proof-of-concept scripts that once demanded ARM64 assembly fluency can now be auto-completed by a prompt like “compile DarkSword for iOS 15.” Frielingsdorf’s lab tested the thesis: an intern with no prior exploit experience produced a working payload in 37 minutes using GitHub Copilot and a Russian-language LLM. “AI won’t write a zero-day, but it will stitch someone else’s into a point-and-shoot package,” he noted.

The body count starts in the grey market
Scrap-metal dealers across Asia already strip logic boards from discarded iPhones to harvest rare metals. For $12 apiece they now sell those boards to data-brokers who resolder a battery, boot into pwned DFU mode and slurp the NAND. A 256 GB iPhone 8 can hold 80 000 photos. At five cents per image on dark-web markets, the math is brutal. One pallet of “dead” phones equals a semester of Ivy-League tuition.
Apple’s advice, repeated verbatim in every support doc, is to “keep your device updated.” That counsel rings hollow for the family iPad Air glued to a kitchen wall as a recipe display, or for the 400 000 iPhone 6 units Verizon still lists on IoT management plans. Owners must choose between trashing functional hardware or accepting a spy in the living room.
The company could, in theory, re-sign a final security-only update for legacy boards. It did so once before in 2019 for the iPhone 4s during the FaceTime eavesdropping fiasco. But the cost-of-revenue accountants inside Apple Park see no upside in resurrecting devices that no longer juice Services revenue. So the patch window stays shut.
Bottom line: the dump is forever
DarkSword won’t make front-page headlines until a celebrity’s ancient iCloud leaks. Yet the tooling is already baked into criminal playlists. Expect bulk NAND extraction services to advertise on Telegram within weeks, priced per gigabyte. And every dusty iPhone drawer in the world just became a potential evidence locker—no warrant necessary, only Wi-Fi and curiosity.
