A Stealthier Evolution of a Known iOS Threat
Researchers at iVerify have disclosed a new variant of the DarkSword iOS exploit kit, dubbed P7 DarkSword after the "p7_" variable prefixes the threat actor uses in its modified code. DarkSword itself was first documented in March 2026 by Google's Threat Intelligence Group, iVerify, and Lookout as a commercial-grade toolkit chaining multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject payloads directly into SpringBoard, the process that runs the iOS home screen.
P7 keeps that same exploit chain but overhauls the kit's data-theft and operational-security features — making it both more dangerous to cryptocurrency holders and harder for defenders to spot in network traffic.
What's New in P7
Local Processing Before Exfiltration
Earlier DarkSword variants exfiltrated entire databases wholesale. P7 instead extracts keychain data into JSON on the device itself before sending it out, and does the same for targeted cryptocurrency wallet apps — including imToken and BitKeep — pulling recovery phrases, balances, and keystore data without shipping raw database files off the phone. Researchers say the kit's wallet-scanning logic can reach more than 25 different wallet applications in total.
Live Remote Command Channel
P7 polls attacker-controlled infrastructure roughly every 15 seconds for new commands, giving operators near-real-time control over an infected device. Supported commands include:
| Capability | Description |
|---|---|
| Shell execution | Runs OS commands (ls, cat, mkdir, rm, ps, and similar) |
| File transfer | Downloads and uploads arbitrary files |
| Camera capture | Exfiltrates photos captured on demand |
| App enumeration | Lists installed apps and extracts their data |
| Wallet scanning | Locates and extracts cryptocurrency wallet data |
| Notes & Photos upload | Uploads Apple Notes and Photos database contents |
| Device fingerprinting | Collects device metadata and scans the filesystem |
Beyond wallets, P7 also reaches SMS messages, call history, contacts, voicemail, location history, saved Wi-Fi passwords, Apple Health data, and iCloud Keychain contents.
Better Operational Security
P7 drops the debug logging over HTTP and syslog that made earlier DarkSword infections easier to spot, and uses browser localStorage to mark devices as already exploited — preventing redundant, noisier re-exploitation attempts against the same target.
Targeting and Distribution
The original DarkSword chain targeted iPhones running iOS 18.4 through 18.7. iVerify has observed P7 campaigns attempting — with limited, AI-assisted success — to extend the chain to iOS 26.x, suggesting operators are actively trying to keep pace with Apple's latest releases rather than retiring the kit against unsupported devices.
Distribution relies on compromised web infrastructure rather than app-store delivery:
- Abandoned e-commerce analytics domains, re-registered by the threat actor and used to inject malicious JavaScript into old tracking tags still loaded by stale pages
- Fake cryptocurrency trading platforms serving the exploit chain directly to visitors
- Fake Snapchat-themed sites and bogus invitation pages used as initial lures
One documented campaign used the domain ecomtrack[.]io (written here with brackets, not as a clickable link) to redirect visitors through scam pages toward a fraudulent crypto-trading site that ultimately delivered the exploit chain.
Who's Behind It
iVerify's research points to multiple, unrelated operators using the same kit rather than a single actor — consistent with DarkSword's commercial, "exploitation-as-a-service" business model:
- PARS Defense, a Turkish commercial surveillance vendor
- Star Blizzard (COLDRIVER), a Russia-aligned state-backed group
- Unknown Chinese-speaking operators running infrastructure hosted on Tencent and Shenyang-based providers, showing signs of an agent/reseller hierarchy
This spread of customers — from a surveillance vendor to a state-aligned espionage group to apparent cybercriminal resellers — illustrates how a single mercenary exploit chain can end up serving very different missions once it's sold or leased out.
Why This Matters
P7 DarkSword is a reminder that mercenary iOS exploit kits don't stay static after initial disclosure — operators iterate on both capability and stealth, in this case pivoting toward the kind of on-device data processing and cryptocurrency targeting usually associated with financially motivated malware rather than pure surveillanceware. The attempted iOS 26.x support also signals continued investment in keeping the chain viable against current devices, not just unpatched legacy ones.
Apple has previously shipped fixes for vulnerabilities associated with the DarkSword chain, including CVE-2025-24201 (patched in iOS 18.3.2) and CVE-2025-31200 (patched in iOS 18.4.1).
Protective Measures
- Keep iOS fully updated — install security updates as soon as they're available rather than deferring them
- Be wary of links from unfamiliar crypto-trading sites, "update" prompts, or unsolicited invitation pages, especially those arriving via social media or messaging apps
- Enable Lockdown Mode on iOS for journalists, activists, executives, or anyone else who may be a targeted-surveillance risk
- Use a hardware wallet or air-gapped signing device for significant cryptocurrency holdings rather than keeping recovery phrases accessible to a mobile wallet app
- Monitor for unusual battery drain, data usage, or app behavior, which can indicate background exfiltration activity