Skip to content
Security & Trust

iVerify finds DarkSword iPhone variant that steals keychain and wallet data

P7 reduces its on-device footprint and takes live commands from attackers, iVerify reports

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
iVerify finds DarkSword iPhone variant that steals keychain and wallet data
In brief
  • iVerify found P7 DarkSword, a variant of an iPhone exploit kit that reduces its on-device footprint, steals keychain and crypto-wallet data, and takes live commands from attackers.
  • iVerify judges the P7 authors competent, unlike the authors of many AI-assisted variants it has seen. That is its assessment of one variant.
  • DarkSword in general targets iOS 18.4 to 18.7, and attackers have tried to extend it to iOS 26.x. Check those phones and ask who investigates partial alerts.

A copy of a spy tool is only as dangerous as the people who edit it. That is the idea behind iVerify's new research on P7 DarkSword, a variant of an iPhone exploit kit. It is one variant, so the lesson is narrow. But it shows what defenders should watch: how the tool is being changed, not just that it exists.

What iVerify found

In August 2026, an alert on a customer's iPhone looked like a known DarkSword detection, but not quite. With the customer's consent, iVerify collected more forensic evidence. It showed a variant iVerify had not seen before. The team named it P7 DarkSword, after the p7_ prefix the attacker put on variables in the modified code.

Separately, the team searched public internet data through Validin for more samples of DarkSword and Coruna. Coruna is another iOS exploit kit, according to The Hacker News. iVerify used its own tools to download whatever code the hits served. Known file traces from the infected phone led it to a domain hosting what looked like another version of the same spyware.

Compared with the variants iVerify usually sees, P7 reduces its on-device footprint. It steals keychain and crypto-wallet data on the phone. It also supports two-way communication with the attacker's servers.

A judgment about skill, drawn from one variant

iVerify says many of the DarkSword variants it observes are AI-assisted. It says P7 is different. Its authors put real effort into their changes, and those changes showed competence. In iVerify's words, they understood the code they were modifying. That is iVerify's assessment after reading the code.

The Hacker News adds a contrast. It reports that over the past month iVerify watched other actors try, and fail, to port the kit to iOS 26.x, probably with help from large language model (LLM) tools, the technology behind AI chat assistants.

The sources leave gaps. They do not say which iOS versions P7 targets. They do not say whether P7's authors used AI. They do not say how those authors got the code. So this is not a test of AI against human skill.

The narrower lesson is this. DarkSword operators are actively iterating, per iVerify, and the quality of that work varies. Defenders cannot assume every new variant will be clumsy.

How the implant works

The Hacker News says the DarkSword kit chains several iOS vulnerabilities. It escapes the browser's sandbox, gains kernel-level control, then places its payload in SpringBoard. SpringBoard is the iOS program that draws the home screen and starts apps. iVerify says P7 routes all contact with the attacker's servers through it.

The implant sends a /beacon request every 15 seconds. The reply carries commands for the phone to run. The attacker can change the interval with a sleep command. This is the two-way channel. The attacker steers the phone live instead of waiting for a one-time data dump.

Dedicated commands can upload photos, list installed apps and copy Apple Notes databases. Another pulls data from the imToken wallet app, and one runs JavaScript inside the implant. Earlier versions copied the whole keychain database and processed it on the attacker's servers. P7 extracts the keychain into a JSON file on the phone first. The keychain is where iOS stores saved credentials.

On footprint, iVerify says P7 removes debug logging over HTTP requests and in the system log. It also reduces process injections. It uses browser localStorage, a small data store in the browser, to avoid exploiting the same phone twice.

None of this made P7 invisible. iVerify found it through forensic artifacts on the phone. Its post lists many indicators, such as domains, file paths and file hashes, that teams can search for.

15 seconds
Beacon interval
Source: iVerify, P7 DarkSword research (reported by The Hacker News, October 9, 2026)
18.4 to 18.7
iOS versions DarkSword targets (kit in general)
Source: Google Threat Intelligence Group, iVerify and Lookout, March 2026 (via The Hacker News, October 9, 2026)
November 2025
DarkSword first detected in the wild
Source: The Hacker News, citing prior DarkSword reporting (October 9, 2026)

What is not known

iVerify's report covers one investigated infection and its hunting results. It does not say how many people P7 has hit. The Hacker News lists DarkSword attacks in Saudi Arabia, Turkey, Malaysia and Ukraine. Those involve the kit in general, not P7.

The report does not name who runs P7. It also does not say which iOS versions P7 targets. The sample's network requests carry a fixed browser identifier naming iOS 18.5, but the report does not explain what that implies.

For detection, the post offers many indicators. Teams can search for the domain mzpo30[.]cam. They can also look for a temporary file named keychain_c2_dump.json.tmp in the phone's /private/var/tmp folder.

What to ask your team

First, which phones that approve payments, read email or hold company credentials run iOS 18.4 to 18.7? That is the range reported for DarkSword in general. Attackers have also tried to extend the kit to iOS 26.x, so treat the range as a starting point for inventory, not a boundary.

Second, can your mobile security tooling check iVerify's published indicators? Ask for a yes or a date.

Third, who investigates an alert that only partly matches a known threat? iVerify found P7 because it pursued such an alert. Its report says investigating partial or heuristic detections can lead to new discoveries and better detection.

Fourth, do staff keep crypto wallets or sensitive notes on work phones? P7 has dedicated handlers for both.

A tool that reportedly leaked or was resold is a starting point for whoever picks it up. Watch how it is being changed, not only that it exists.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: iVerify.

Share this insight