P7 DarkSword: New iOS Exploit Kit Variant Targets iPhone Users for Credential and Crypto Wallet Theft
Cybersecurity researchers have uncovered a previously undocumented variant of the DarkSword iOS exploit kit, dubbed P7 DarkSword, that introduces stealth improvements, expanded data theft capabilities, and two-way communication with attacker-controlled infrastructure.
According to mobile security company iVerify, the new variant reduces its on-device footprint and adds capabilities to steal iCloud Keychain data, application information, photos, notes, and cryptocurrency wallet data. The name P7 comes from the p7_ variable prefix found in modifications to the original DarkSword code.
The discovery highlights the continued spread of leaked iOS exploit technology among financially motivated threat actors and operators offering exploitation services.
What Is DarkSword?
DarkSword is an iOS exploit kit publicly documented in March 2026 by Google Threat Intelligence Group, iVerify, and Lookout. Researchers reported that it had been detected in real-world attacks as early as November 2025.
The toolkit chains multiple iOS vulnerabilities to escape the browser sandbox, escalate privileges to the kernel level, and inject its main payload into SpringBoard, the iOS process responsible for the Home Screen and application launching.
Researchers believe the toolkit originated as a commercial product that subsequently reached secondary markets, where it was acquired by financially motivated operators and other threat actors.
Previous campaigns using DarkSword targeted devices running iOS versions between 18.4 and 18.7. Reported victims and targets included users in Saudi Arabia, Turkey, Malaysia, and Ukraine.
Threat actors have reportedly used fake Snapchat-themed websites and fraudulent invitation lures to deliver the exploit kit. Other campaigns have targeted Apple devices through decoy Apple ID sign-in pages.
How P7 DarkSword Differs From Earlier Versions
The newly identified variant introduces several changes intended to improve stealth and expand the amount of information that can be collected from compromised devices.
According to iVerify, P7 DarkSword:
- Reduces its on-device footprint.
- Removes debug logging associated with HTTP requests and system logging.
- Uses browser
localStorageto help prevent repeated exploitation. - Extracts keychain information into JSON on the device before transmitting it.
- Adds two-way command-and-control communication.
- Expands theft capabilities to include cryptocurrency wallet information and additional application data.
Earlier variants reportedly copied the keychain database and transferred it to attacker infrastructure for processing. P7 DarkSword instead extracts relevant information locally before exfiltration.
The implant is injected into SpringBoard, which handles communications with the attacker's infrastructure.
Remote Command-and-Control Capabilities
P7 DarkSword communicates with its command-and-control (C2) infrastructure through the injected SpringBoard implant. By default, it polls for instructions every 15 seconds and can send heartbeat messages, installed application lists, and stolen information to its operator.
The implant supports a range of remote commands, including:
CommandFunctionexecute_commandExecutes operating system commands on the compromised device.lsLists directory contents.downloadReads a file and uploads it to the C2 server.photosUploads photos from the device's media directory.appsEnumerates application containers and extracts bundle identifiers.execExecutes JavaScript within the implant runtime.file_uploadScans specified paths recursively and uploads matching files.basic_infoCollects and transmits device information.disk_scanScans the filesystem and reports file, directory, and symbolic-link metadata.ios_app_dataLocates application containers and uploads selected application files.wallet_scanSearches for installed cryptocurrency wallet applications.wallet_extractExtracts wallet-related information from the imToken application.memo_scanCollects Apple Notes databases.photo_scanCollects photos from Apple Photos.sleepChanges the interval between C2 communications.exitStops the implant's polling loop.
These capabilities give operators considerable control over compromised devices, allowing them to collect information selectively, inspect files, and adjust the implant's behavior remotely.
Censys Identifies Exposed DarkSword and Coruna Infrastructure
The disclosure comes as attack surface management company Censys reported discovering exposed directories on five hosts containing components associated with DarkSword and Coruna, another iOS exploit kit.
Coruna was previously documented in attacks targeting iPhones running iOS versions between 13.0 and 17.2.1. Its payloads include cryptocurrency wallet theft capabilities that can collect recovery phrases, balances, and keystore data.
According to Censys, operators can deploy DarkSword and Coruna together using their own C2 infrastructure.
The five identified hosts were associated with different parts of the operation:
- 43.134.165[.]205: Hosted DS-Fusion v1.0, a combined package containing DarkSword and Coruna components.
- 166.88.95[.]90: Served as an implant C2 server. Researchers observed two Chinese iOS devices polling a beacon page repeatedly on September 6, 2026.
- 23.148.212[.]237: Hosted an analysis workspace containing evidence of development work on iOS 26 exploit chains, including work involving CVE-2026-31001. These exploits were not part of the documented DarkSword or Coruna kits.
- 47.102.192[.]23: Served as a staging host for Coruna.
- 156.239.230[.]120: Exposed a broader C2 platform and was observed polling a device on September 15, 2026.
The findings indicate that the infrastructure supports multiple stages of exploitation, payload delivery, and device management.
Two Previously Undocumented CVEs Identified
Analysis of the production server's exploit registry revealed two vulnerabilities used by the DarkSword exploit kit that had not previously been documented as part of the toolkit.
- CVE-2025-24201: An out-of-bounds write vulnerability in Apple's WebKit engine that can allow an attacker to escape the Web Content sandbox. Apple addressed the issue in iOS 18.3.2 and iPadOS 18.3.2.
- CVE-2025-31200: A memory corruption vulnerability in the Core Audio framework that can enable code execution when processing a specially crafted malicious audio stream. Apple addressed it in iOS 18.4.1 and iPadOS 18.4.1.
The inclusion of these vulnerabilities illustrates how the exploit kit combines multiple weaknesses to progress from browser-level access to deeper system compromise.
Researchers Suspect a Chinese-Speaking Exploitation Service
Censys researchers suspect that the exposed infrastructure is operated by a Chinese-speaking threat actor focused on cryptocurrency theft. However, the operator's identity and affiliations remain unknown.
Researcher Aidan Holland said the platform appears to operate as an exploitation-as-a-service operation, with an administrative panel supporting an agent and reseller model.
A copy of the production server reportedly contained:
- 11 cryptocurrency wallet recovery phrases.
- 179 directories containing data collected from devices.
- A control-plane roster listing 75 accounts.
Censys also identified a separate China-based operator using the same toolkit with its own C2 infrastructure at 66ds[.]lol. This operator had added BitKeep as a cryptocurrency wallet target that was not present in the exposed-directory dataset.
The findings suggest that DarkSword and related tools are circulating among multiple operators rather than remaining under the control of a single group.
How to Protect Your iPhone
The most important defensive measure is to keep iOS updated. The documented exploit chain targets vulnerable iOS versions, so users and organizations should:
- Install the latest available iOS security updates compatible with their devices.
- Avoid suspicious websites and advertisements, particularly pages prompting unexpected downloads, logins, or unusual verification steps.
- Review cryptocurrency wallet security. If a device is suspected of compromise, use a separate trusted device to secure wallet accounts and move funds where appropriate.
- Monitor managed devices for suspicious browser activity, unexpected network connections, and signs of mobile compromise.
- Investigate suspected infections using a qualified mobile incident response team rather than relying only on routine app or file checks.
Organizations should also review the infrastructure indicators published by Censys and iVerify, while recognizing that IP addresses and domains can change over time.
Key Takeaway
P7 DarkSword demonstrates how a leaked iOS exploit kit can evolve into a more capable surveillance and data-theft platform. Its reduced footprint, on-device keychain extraction, cryptocurrency wallet targeting, and interactive C2 functions increase the risks for users running vulnerable devices.
The discovery of exposed infrastructure associated with both DarkSword and Coruna further highlights the proliferation of advanced mobile exploitation tools among financially motivated operators.
Keeping iOS updated and treating suspected device compromise as a potential credential and cryptocurrency exposure are essential steps in reducing risk.
Research sources: iVerify's P7 DarkSword technical report and Censys's DarkSword and Coruna infrastructure investigation.