SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
iVerify discloses P7 DarkSword, a reworked variant of a leaked iOS exploit kit focused on stability, stealth and stolen data quality
iVerify disclosed P7 DarkSword, a reworked variant of a leaked iOS exploit kit for iPhones on iOS 18.4 to 18.7 that steals keychain and crypto-wallet data. The commercial chain leaked onto a second-hand market, where financially motivated operators have been buying it since late 2025.
The Watch · Security desk

What happened
- Where earlier variants copied the whole keychain database off the phone to parse on attacker infrastructure, P7 extracts the keychain into JSON on the device before sending it.
- The task set lets operators run operating-system commands including memory dumps, execute arbitrary JavaScript in the implant, pull imToken wallet data, and upload Apple Notes databases and Photos.
- P7 drops its debug logging over HTTP and syslog and marks browser localStorage so it will not re-exploit a phone it already controls.
- Every 15 seconds the implant polls the attacker's server for its next task and returns a heartbeat and the list of installed apps.
- In August 2026 Censys attributed a campaign to an unknown Chinese-speaking actor that paired the kit with a fake Apple ID sign-in page.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure With financially motivated buyers in the mix, the exposed population is anyone holding crypto or credentials on a vulnerable iPhone, not the narrow espionage target list the kit started with.
- capability Two-way control means an operator can return to a compromised phone and re-task it on demand rather than grab data once.
- decision The kit has not been made to work on iOS 26.x, so for mobile fleets the cheapest control is moving devices off the iOS 18 line it still targets.
- precedent Because the code leaked and is already being forked, expect wallet theft to spread past imToken to other wallets in later builds.
iVerify assesses the exploit chain as a commercial product that landed in a second-hand market, where financially motivated operators and other actors have bought it since late 2025. [7] The variant is named P7 after the "p7_" prefix its author added to changes in the original DarkSword code. [2]
The chain strings together several iOS flaws to break out of the browser sandbox, escalate to kernel privileges, and inject its payload into SpringBoard, the process that runs the home screen and app launches. [6] "The implant is injected into the SpringBoard process, which handles all communication with the attacker's infrastructure," iVerify said. [17]
The Turkish surveillance vendor PARS Defense delivered the kit through a fake Snapchat-themed site, and the Russia-aligned actor Star Blizzard, also tracked as COLDRIVER, used fake invitation lures. [9][10] The campaigns hit targets in Saudi Arabia, Turkey, Malaysia, and Ukraine. [8]
DarkSword was detected in the wild in November 2025 [5] and documented publicly in March by Google's Threat Intelligence Group, iVerify, and Lookout. [4] The leak followed that disclosure, and the forks since have concentrated on stability, stealth, and the quality of stolen data. [13][14] Last month iVerify watched "multiple unsuccessful, likely LLM-assisted attempts to update the framework to support iOS 26.x." [12] Separately, Censys found open directories on five hosts holding components for both DarkSword and Coruna, [20] a second iOS exploit kit documented this year that targets older iPhones running iOS 13.0 to 17.2.1. [21]
What to watch
- Whether iVerify or Apple ties the chain to specific CVEs and whether a shipped iOS build has already patched them.
- Whether a working iOS 26.x port emerges after the failed LLM-assisted attempts iVerify observed.
- Whether wallet_extract expands beyond imToken to other crypto wallets in later forks.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption40
- Hype gap+5
- Incentives30
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
iVerify published a report Thursday disclosing a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.
- [2]
The variant is named P7 after the 'p7_' variable prefix the threat actor used in its changes to the original DarkSword code.
- [3]
DarkSword targets iPhones running iOS versions between 18.4 and 18.7.
- [4]
DarkSword was first publicly documented in March by Google Threat Intelligence Group, iVerify, and Lookout.
- [6]
The toolkit chains multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject its main payload into SpringBoard, the iOS process that handles app launches and the home screen.
- [7]
iVerify assesses the exploit chain as a commercial product that landed in a second-hand market, from where financially motivated operators and other threat actors acquired it since late 2025.
- [8]
The kit has been used in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine.
- [9]
A Turkish commercial surveillance vendor named PARS Defense delivered the kit through a fake Snapchat-themed website.
- [10]
The Russia-aligned threat actor Star Blizzard, also known as COLDRIVER, used the kit with fake invitation lures.
- [11]
In August 2026, Censys detailed a campaign by an unknown Chinese-speaking threat actor that targeted Apple iOS devices with the kit and served an Apple ID decoy sign-in page.
- [12]
multiple unsuccessful, likely LLM-assisted attempts to update the framework to support iOS 26.x
- [13]
iVerify said the leaked variants focus on stability, stealth, and the quality of stolen data.
- [14]
The attempts to extend the kit were fueled by the leak of the exploit kit shortly after its public disclosure.
- [15]
P7 eliminates debug logging over HTTP requests and syslog and uses browser localStorage to prevent re-exploitation.
- [16]
Unlike prior variants that copied and exfiltrated the keychain database to process on attacker infrastructure, P7 extracts keychain data into JSON on the phone before exfiltration.
- [17]
The implant is injected into the SpringBoard process, which handles all communication with the attacker's infrastructure
- [18]
The implant polls for commands every 15 seconds, sends a heartbeat, sends a list of installed applications, and transmits iCloud Keychain data and data from Apple Notes, Photos, and cryptocurrency wallets.
- [19]
P7's command set includes execute_command to run operating-system commands such as memdump, exec to run arbitrary JavaScript inside the implant runtime, wallet_scan and wallet_extract for the imToken wallet, memo_scan for Apple Notes databases, and photo_scan for Apple Photos.
- [20]
Censys identified open directories on five hosts carrying components related to DarkSword and Coruna.
- [21]
Coruna is another iOS exploit kit uncovered this year, weaponized against iPhones running iOS versions between 13.0 and 17.2.1.
Sources
1 independent publisher whose own reporting we read for this story.
- thehackernews.comP7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Crypto Wallet Credential TheftFollow
- iOS SecurityFollow
- Mobile exploit kitsFollow
- Commercial surveillance vendorsFollow