P7 DarkSword iOS Variant Steals Crypto Wallets and Accepts Remote Commands, iVerify Says

iVerify reports P7 DarkSword iOS variant steals keychain and wallet data and accepts remote commands; Censys describes linked servers and operator claims.

P7 DarkSword iOS Variant Steals Crypto Wallets and Accepts Remote Commands, iVerify Says
Vulnerabilities

Illustrative image generated with AI

A new variant of the DarkSword iOS exploit kit, called P7, adds theft of iCloud Keychain and cryptocurrency-wallet data and lets operators send commands to infected iPhones. That is according to a report from mobile security firm iVerify, as relayed by The Hacker News. Separately, Censys says it found exposed servers tied to a Chinese-speaking operator who runs the kit as a service.

The P7 capabilities and the infrastructure details are claims by iVerify and Censys as reported in that article. The two Apple vulnerabilities the article ties to the kit are a different matter. Their NVD and CISA KEV entries date from spring 2025 and say nothing about DarkSword.

What changed in P7

The name comes from the p7_ variable prefix in the modified DarkSword code, according to iVerify. Compared with earlier versions, the variant:

  • drops the debug logging that sent HTTP requests and syslog output;
  • uses the browser's localStorage so the device does not have to be exploited again;
  • extracts the keychain into JSON on the phone before exfiltration, rather than copying the whole database to attacker infrastructure.

The implant is injected into SpringBoard, the iOS process that handles app launches and the home screen. iVerify says SpringBoard also handles all communication with the attacker's servers.

The implant polls its command server every 15 seconds, sends heartbeat messages and reports the list of installed apps. It also transmits iCloud Keychain data and content from Apple Notes, Photos and crypto-wallet apps.

Remote commands

The two-way channel is the main addition. iVerify lists these commands the implant can receive:

  • execute_command runs system commands such as ls, cat, mkdir, rm, ps, memdump, netstat and whoami.
  • download, file_upload and disk_scan read a file, scan chosen paths recursively, or crawl the filesystem from / and upload a report.
  • photos and photo_scan pull images, including from /var/mobile/Media/DCIM; memo_scan uploads Apple Notes databases.
  • apps and ios_app_data enumerate app containers and bundle IDs, then upload selected files.
  • wallet_scan looks for installed wallet apps, and wallet_extract pulls data from the imToken wallet.
  • exec runs arbitrary JavaScript inside the implant's runtime.
  • basic_info sends device metadata, sleep changes the polling interval, and exit stops the beacon loop and the implant.

iVerify also says that as recently as last month it saw "multiple unsuccessful, likely LLM-assisted attempts" to adapt the framework to iOS 26.x. It attributes this to the kit's leak shortly after public disclosure. The variants it describes focus on stability, stealth and the quality of stolen data.

Censys: open directories and a reseller panel

Censys researcher Aidan Holland is quoted on open directories found on five hosts. They hold components linked to DarkSword and a companion kit called Coruna. Censys describes Coruna as a payload that runs in the browser session after DarkSword's stages land, with modules that take recovery phrases, balances and keystore data from iOS apps. It says operators run the two kits together against their own command infrastructure.

A copy of a production server, per Censys, held 11 victim recovery phrases, 179 per-device loot directories and a roster of 75 control-plane accounts. Censys says the platform is a Chinese-speaking exploitation-as-a-service operation, with an agent and reseller model in the admin panel. It suspects a Chinese-speaking actor runs it for wallet theft but says who is behind it is unknown. The figures count different things and are not comparable.

Censys also reports a separate China-based operator using the same kit against its own server, 66ds[.]lol, with an extra BitKeep wallet target absent from the open directories. It ties that operator to Tencent and Shenyang hosting and a unique self-signed certificate authority. An August 2026 campaign by an unidentified Chinese-speaking actor, which paired the kit with a fake Apple ID sign-in page, was also detailed by Censys.

Hosts Censys reported:

  • 43.134.165[.]205: serves DS-Fusion v1.0 (DarkSword Fusion), a single package combining DarkSword and Coruna.
  • 166.88.95[.]90: implant command server. On 2026-09-06 two real Chinese iOS devices, at 183.154.173[.]30 and 182.239.114[.]223, polled a beacon page every three seconds for several hours.
  • 23.148.212[.]237: analysis workspace showing an operator developing iOS 26 exploit chains, for example for CVE-2026-31001. Per the article, these chains are not covered by DarkSword or Coruna.
  • 47.102.192[.]23: staging host for Coruna.
  • 156.239.230[.]120: exposes the full command platform; seen polling a device on 2026-09-15.

Background on the kit

According to the article, DarkSword was first documented publicly in March by Google's Threat Intelligence Group (GTIG), iVerify and Lookout. It was detected in the wild in November 2025 and targets iPhones running iOS 18.4 through 18.7. The article says the exploit chain is assessed to be a commercial product that somehow ended up in a second-hand market. From there, it says, financially motivated operators and other actors have acquired it since late 2025.

Named users include PARS Defense, a Turkish commercial surveillance vendor, which used a fake Snapchat-themed site. Star Blizzard (COLDRIVER), a Russia-aligned actor, used fake-invitation lures. The reported targets are Saudi Arabia, Turkey, Malaysia and Ukraine, with no per-country attribution. Coruna, per the article, targets iOS 13.0 through 17.2.1.

The two Apple flaws

The article says an analysis of the production server's exploit registry showed the kit includes two CVE identifiers "not previously documented" as part of it. That link comes from the registry analysis as reported there. The NVD and KEV entries for both flaws describe only the WebKit and Core Audio bugs, their fixes and exploitation status, and do not mention DarkSword.

CVE-2025-24201 is an out-of-bounds write (CWE-787) in WebKit, rated CVSS 10. It lets malicious web content break out of the Web Content sandbox. CISA added it to KEV on 2025-03-13, with a federal remediation deadline of 2025-04-03. Apple's fixes:

  • Safari 18.3.1
  • iOS and iPadOS 15.8.4, 16.7.11 and 18.3.2
  • iPadOS 17.7.6
  • macOS Sequoia 15.3.2
  • visionOS 2.3.2
  • watchOS 11.4

CVE-2025-31200 is a memory corruption flaw (CWE-119) in Core Audio, rated CVSS 9.8. Processing an audio stream in a malicious media file can lead to code execution. It entered KEV on 2025-04-17, with a deadline of 2025-05-08. Apple's fixes:

  • iOS and iPadOS 18.4.1
  • macOS Sequoia 15.4.1
  • tvOS 18.4.1
  • visionOS 2.4.1
  • watchOS 11.5

For both, CISA's required action is to apply the vendor's mitigations, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Apple's advisory text says it is aware of reports that each issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.

Other KEV entries for Apple and Debian have been added in the last 90 days: CVE-2015-3306 (2026-10-08), CVE-2026-86950 (2026-09-29), CVE-2025-39682 (2026-09-18) and CVE-2026-65400 (2026-08-18).

What to check

The patches above are the only remediation listed; no P7-specific mitigations are given in the material reviewed. Updating iPhones to current iOS releases is the direct step. Network teams can search logs for the Censys hosts and 66ds[.]lol.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →