New P7 variant of DarkSword iOS exploit kit steals keychain and crypto wallet data
iVerify has documented a DarkSword variant that adds keychain and cryptocurrency wallet theft plus two-way command-and-control, The Hacker News reports.
At a glance
- The P7 variant adds keychain and crypto-wallet theft, two-way C2 and a smaller on-device footprint, according to iVerify.
- DarkSword targets iOS 18.4 through 18.7; two newly linked flaws, CVE-2025-24201 and CVE-2025-31200, are already patched.
- The kit has been used in attacks on targets in Saudi Arabia, Turkey, Malaysia and Ukraine.
- Censys found a server holding 11 victim recovery phrases and 179 device loot directories.
A new variant of the DarkSword iOS exploit kit has gained the ability to steal iCloud Keychain data and cryptocurrency wallet contents and to take remote commands from its operators, according to a report from mobile security firm iVerify covered by The Hacker News on October 9. The variant, which iVerify calls P7, shows how a commercial exploit chain that reached a second-hand market is now being repurposed for financially motivated theft.
What happened
According to The Hacker News, DarkSword chains multiple vulnerabilities to escape the browser sandbox, escalate to kernel privileges and inject its payload into SpringBoard, the iOS process that manages the home screen and app launches. The kit was first detected in the wild in November 2025 and publicly documented in March 2026 by Google Threat Intelligence Group, iVerify and Lookout. The publication says the chain is assessed to be a commercial product that has been acquired by financially motivated and other threat actors since late 2025.
iVerify named the new variant after the p7_ variable prefix its operator added to the original code.
Technical details
Compared with earlier versions, P7 reduces its on-device footprint, adds keychain and crypto-wallet theft, introduces two-way command-and-control (C2) communication and stops debug logging, according to the report. It polls for commands every 15 seconds, sends a list of installed apps and can exfiltrate data from Apple Notes, Photos and cryptocurrency wallets. Supported commands include wallet_scan, wallet_extract, which targets the imToken wallet app, disk_scan and exec.
DarkSword targets iOS 18.4 through 18.7, while a companion kit called Coruna covers iOS 13.0 through 17.2.1. The Hacker News says two vulnerabilities not previously documented as part of the kit, CVE-2025-24201 in WebKit and CVE-2025-31200 in Core Audio, are linked to it; Apple fixed them in iOS 18.3.2 and iOS 18.4.1 respectively. iVerify also noted several unsuccessful, likely AI-assisted attempts to add support for iOS 26.x, while Censys observed an operator developing separate exploit chains for iOS 26.
Who is affected
The Hacker News reports that the kit has been used against targets in Saudi Arabia, Turkey, Malaysia and Ukraine. Turkish commercial surveillance vendor PARS Defense used a fake Snapchat-themed site, and Russia-aligned Star Blizzard used fake invitation lures. Censys separately found a production server copy holding 11 victim recovery phrases and 179 device loot directories, which it attributes to a suspected Chinese-speaking operator focused on cryptocurrency theft whose identity is unknown.
What to do
The kit relies on older iOS releases, so the most effective defense is updating iPhones and iPads to the latest supported version. Organizations can block the infrastructure listed in the report, including 166.88.95[.]90, 43.134.165[.]205, 156.239.230[.]120 and the domain 66ds[.]lol. Cryptocurrency users should avoid storing recovery phrases in Notes or Photos and should treat unsolicited links to invitation or social media-themed pages with caution.
Related CVEs
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



