Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

iVerify discloses P7 DarkSword, a reworked variant of a leaked iOS exploit kit focused on stability, stealth and stolen data quality

iVerify disclosed P7 DarkSword, a reworked variant of a leaked iOS exploit kit for iPhones on iOS 18.4 to 18.7 that steals keychain and crypto-wallet data. The commercial chain leaked onto a second-hand market, where financially motivated operators have been buying it since late 2025.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying iVerify discloses P7 DarkSword, a reworked variant of a leaked iOS exploit kit focused on stability, stealth and stolen data quality
Generated illustration

What happened

  • Where earlier variants copied the whole keychain database off the phone to parse on attacker infrastructure, P7 extracts the keychain into JSON on the device before sending it.
  • The task set lets operators run operating-system commands including memory dumps, execute arbitrary JavaScript in the implant, pull imToken wallet data, and upload Apple Notes databases and Photos.
  • P7 drops its debug logging over HTTP and syslog and marks browser localStorage so it will not re-exploit a phone it already controls.
  • Every 15 seconds the implant polls the attacker's server for its next task and returns a heartbeat and the list of installed apps.
  • In August 2026 Censys attributed a campaign to an unknown Chinese-speaking actor that paired the kit with a fake Apple ID sign-in page.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure With financially motivated buyers in the mix, the exposed population is anyone holding crypto or credentials on a vulnerable iPhone, not the narrow espionage target list the kit started with.
  • capability Two-way control means an operator can return to a compromised phone and re-task it on demand rather than grab data once.
  • decision The kit has not been made to work on iOS 26.x, so for mobile fleets the cheapest control is moving devices off the iOS 18 line it still targets.
  • precedent Because the code leaked and is already being forked, expect wallet theft to spread past imToken to other wallets in later builds.

iVerify assesses the exploit chain as a commercial product that landed in a second-hand market, where financially motivated operators and other actors have bought it since late 2025. [7] The variant is named P7 after the "p7_" prefix its author added to changes in the original DarkSword code. [2]

The chain strings together several iOS flaws to break out of the browser sandbox, escalate to kernel privileges, and inject its payload into SpringBoard, the process that runs the home screen and app launches. [6] "The implant is injected into the SpringBoard process, which handles all communication with the attacker's infrastructure," iVerify said. [17]

The Turkish surveillance vendor PARS Defense delivered the kit through a fake Snapchat-themed site, and the Russia-aligned actor Star Blizzard, also tracked as COLDRIVER, used fake invitation lures. [9][10] The campaigns hit targets in Saudi Arabia, Turkey, Malaysia, and Ukraine. [8]

DarkSword was detected in the wild in November 2025 [5] and documented publicly in March by Google's Threat Intelligence Group, iVerify, and Lookout. [4] The leak followed that disclosure, and the forks since have concentrated on stability, stealth, and the quality of stolen data. [13][14] Last month iVerify watched "multiple unsuccessful, likely LLM-assisted attempts to update the framework to support iOS 26.x." [12] Separately, Censys found open directories on five hosts holding components for both DarkSword and Coruna, [20] a second iOS exploit kit documented this year that targets older iPhones running iOS 13.0 to 17.2.1. [21]

What to watch

  • Whether iVerify or Apple ties the chain to specific CVEs and whether a shipped iOS build has already patched them.
  • Whether a working iOS 26.x port emerges after the failed LLM-assisted attempts iVerify observed.
  • Whether wallet_extract expands beyond imToken to other crypto wallets in later forks.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption40
Hype gap+5
Incentives30
Confidence50
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    iVerify published a report Thursday disclosing a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.

    ReportedSupportedSource: iVerifyView cited source
  2. [2]

    The variant is named P7 after the 'p7_' variable prefix the threat actor used in its changes to the original DarkSword code.

    ReportedSupportedView cited source
  3. [3]

    DarkSword targets iPhones running iOS versions between 18.4 and 18.7.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thehackernews.com

    1 article · October 9, 2026

    P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Entities

Loading related stories