Ukraine's State Service of Special Communications and Information Protection (SSSCIP) has published a report warning that Russian hackers are increasingly targeting smartphones used by Ukrainian military personnel and government officials. The warning covers both Android and iOS devices, noting that the growing role of smartphones in military and civilian communications makes them attractive targets for espionage and financially motivated attacks.
For iPhones, the report highlights DarkSword, an exploit kit deployed in watering-hole attacks on compromised news and government websites. DarkSword exploits vulnerabilities in Safari and iOS, potentially infecting a device with little or no action from the victim, then stealing login credentials, messages, contacts, and call histories. Cybersecurity firm Lookout has linked DarkSword to a suspected Russia-aligned operation active since at least late 2025, describing it as a hit-and-run tool that extracts data within minutes and removes traces of itself.
On the Android side, Ukrainian authorities tracked two relatively new groups, UAC-0244 and UAC-0263. UAC-0244 created fake websites impersonating military units and other services to distribute CamelSpy, which collects location, SIM card data, contacts, call logs, and stored images. UAC-0263 used decoy apps for air raid alerts and fuel discounts to deliver BTMOB, a remote-access trojan. These mobile campaigns are part of a broader wave of cyber activity, with CERT-UA recording 3,137 incidents in the first half of 2026, an 8% increase from the previous six months.