Ukraine warns of Russian mobile malware hitting iOS, Android

Russian hackers are going after the smartphones of Ukrainian soldiers and government officials more and more often, using both malicious Android apps and an iPhone exploit kit, according to a new report from Ukraine's State Service of Special Communications and Information Protection (SSSCIP). SSSCIP is the government agency responsible for protecting state communications and cyber defense.

The report, published this week, describes campaigns driven by espionage as well as by financial gain. Both iOS and Android users are in scope.

"The growing role of smartphones in communications among military personnel, government employees and civilians makes them increasingly attractive targets for intelligence gathering, further compromise and financially motivated attacks," the researchers wrote.

DarkSword: iPhone compromise through trusted websites

The most notable tool in the report is DarkSword, an exploit kit built to break into iPhones.

Attackers have used it in watering-hole attacks. In these attacks, hackers compromise legitimate websites that their targets are likely to visit, rather than contacting victims directly. In Ukraine, news sites and government websites were hijacked and used to exploit vulnerabilities in Apple's Safari browser and in iOS itself.

According to SSSCIP, the victim has to do little or nothing for the phone to be infected. Once the device is compromised, the attackers can pull out sensitive data, including:

  • login credentials
  • messages
  • contacts
  • call histories

DarkSword activity against Ukrainian targets has already been tied to a suspected Russia-aligned operation. In March, Lookout reported that a threat actor it tracks as UNC6353 had been using the kit against Ukrainian users since at least late 2025.

Lookout said the group compromised a regional news outlet that covers the war, as well as the website of a local court. The researchers also spotted a possible infection at a Ukrainian food processing company.

DarkSword does not behave like typical spyware that stays on a phone and watches its owner for months. Lookout described it as closer to a "hit-and-run" operation. The kit can grab sensitive information within minutes and then wipe traces of itself from the device.

Fake army tests and air raid apps on Android

On the Android side, Ukrainian authorities are tracking two relatively new groups, UAC-0244 and UAC-0263. The "UAC" labels are identifiers used by Ukrainian responders to track threat clusters. Both groups spread malicious apps through websites built to lure Ukrainian users.

UAC-0244 set up sites impersonating Ukraine's 3rd Army Corps that invited visitors to "take a test." It also ran websites posing as a "men's club" and other services. The group's malware, CamelSpy, collects information about the infected device, including its location, SIM cards, contacts and call logs, as well as images stored on the phone.

UAC-0263 used decoy websites that offered supposed apps for air raid alerts, fuel discounts and other services. Its malware, BTMOB, gives the attackers remote access to infected devices and lets them steal information.

The lures are clearly chosen with the local audience in mind. Air raid alerts and fuel prices are daily concerns for people in Ukraine, and a test linked to a military unit is likely to appeal to service members and recruits.

Part of a wider surge

The mobile campaigns sit within a broader rise in cyber activity aimed at Ukraine. CERT-UA, the country's national computer emergency response team, logged 3,137 cyber incidents in the first half of 2026. That is about 8 percent more than in the previous six months.

Russian pressure on Ukraine's digital space is not limited to phones. Recent weeks have also seen internet outages in Kyiv following Russian strikes on data centers.

Our Take

The report shows how firmly the phone has become a front line. For military personnel and officials, a smartphone holds contacts, messages and call histories, which is exactly what DarkSword and CamelSpy are built to collect. That data is valuable both for intelligence and for follow-up attacks.

DarkSword is the more worrying piece. Watering-hole attacks turn trusted news and government sites into delivery channels, and the "hit-and-run" design suggests the operators care more about speed and stealth than persistence. This may make forensic detection harder, since there is less left on the device to find. It also means that routine iOS patching, like the recent Apple zero-day fix, matters even for users who never click a suspicious link.

The Android campaigns rely on older tricks: fake sites and sideloaded apps with believable local lures. The approach is similar to what criminal groups use elsewhere, for example the RemControl banking malware in Europe and Canada. The overlap between espionage and financial motives in the SSSCIP report suggests that the line between state and criminal tooling on mobile is getting thinner.

For readers outside Ukraine, the lesson is that techniques tested in this conflict rarely stay local. It is worth watching whether DarkSword or similar exploit kits show up against organizations that support Ukraine, and whether CERT-UA's incident count keeps climbing in the second half of 2026.