Russian Hackers Intensify Mobile Espionage Against Ukrainian Officials and Military
A recent Ukrainian government report reveals a significant escalation in Russian-aligned cyberattacks targeting the smartphones of Ukrainian military personnel and government officials. These sophisticated campaigns leverage both Android and iOS exploits, aiming for intelligence gathering, further system compromise, and financial gain.
The **State Service of Special Communications and Information Protection (SSSCIP)** of Ukraine has issued a stark warning regarding the increasing focus of Russian hackers on mobile devices belonging to key Ukrainian figures. The report highlights the critical role smartphones play in communication, making them prime targets for espionage and financially motivated cyber operations.
## DarkSword: A Potent iOS Exploit
One of the most concerning tools identified is **DarkSword**, an exploit kit specifically designed to compromise iPhones. This sophisticated threat is deployed through "watering-hole attacks," where attackers compromise legitimate websites that their intended victims are likely to visit.
In Ukraine, these attacks have involved compromising news and government websites to exploit vulnerabilities within **Apple's Safari browser** and **iOS**. The efficacy of DarkSword lies in its ability to infect an iPhone with minimal or no user interaction. Once compromised, the attackers can exfiltrate sensitive data, including login credentials, messages, contacts, and call histories.
Cybersecurity firm **Lookout** previously linked DarkSword activity to a suspected Russia-aligned hacking operation, tracking the threat actor as **UNC6353**. Lookout reported that UNC6353 has been using DarkSword against Ukrainian users since at least late 2025, compromising a regional news outlet, a local court website, and possibly a Ukrainian food processing company.
Unlike persistent spyware, DarkSword operates as a "hit-and-run" tool, designed to rapidly extract information and then erase its traces from the device within minutes.
## Android Devices Under Siege
Ukrainian authorities are also tracking two relatively new hacking groups, **UAC-0244** and **UAC-0263**, which are distributing malicious Android applications. These groups employ deceptive websites to lure Ukrainian users into downloading their malware.
**UAC-0244** has created fake websites impersonating Ukraine's 3rd Army Corps, inviting visitors to "take a test," and also established sites posing as a "men's club" and other services. This group distributes malware known as **CamelSpy**, capable of collecting extensive device information, including location, SIM card details, contacts, call logs, and stored images.
**UAC-0263**, on the other hand, utilizes decoy websites offering purported apps for air raid alerts, fuel discounts, and other seemingly beneficial services. Their malware, dubbed **BTMOB**, grants hackers remote access to infected devices, enabling them to steal sensitive information.
## A Broader Cyber Offensive
These mobile-centric campaigns are part of a larger surge in cyber activity targeting Ukraine. **CERT-UA**, the countryβs national computer emergency response team, recorded 3,137 cyber incidents during the first half of 2026, marking an approximate 8% increase compared to the preceding six months.