P7 DarkSword variant hides deeper on unpatched iPhones

iVerify says a reworked DarkSword build parses the keychain on-device, polls its server every fifteen seconds and pulls data from crypto wallets.

AppleThreat Staff
2 Min Read

A leaked tool gets a stealthier successor

Mobile security firm iVerify has detailed a variant of the DarkSword iOS exploit kit that trims its footprint and reaches further into a victim’s files than builds seen so far. The sample is tracked as P7 DarkSword, a nod to the p7_ prefix its authors stamped onto edited source code.

What P7 does differently

Older DarkSword builds copied the keychain database off the handset for the operator to process later. The new version parses that keychain into JSON on the phone itself before exfiltration, cutting the trace left behind. It also drops HTTP and syslog debug logging and leans on browser localStorage to record devices it has already hit, so a repeat visit skips a fresh attempt.

Commands and the wallet grab

Once active, the implant plants itself in SpringBoard and polls its server every fifteen seconds for orders. The command set includes arbitrary shell execution, file download, recursive disk scans, app-container extraction, photo and Notes upload, and wallet routines that scan for installed crypto apps and pull data from the imToken wallet. Reporting elsewhere ties the same code to an abandoned analytics domain, re-registered in September, still embedded in online shops and redirecting visitors toward the exploit chain.

Who is exposed

The kit chains flaws affecting iPhones on iOS 18.4 through 18.7, so anyone holding an unpatched handset in that range is a candidate. DarkSword has already been linked to campaigns across Saudi Arabia, Turkey, Malaysia, and Ukraine and to a mix of surveillance operators and state-aligned groups. Researchers note the leaked source has widened the pool of attackers experimenting with it, though many attempts remain broken.

The practical advice has not changed: install current iOS updates and treat unsolicited links that mimic sign-in pages as hostile.

Share This Article