Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
iVerify has identified P7 DarkSword, a new variant of the DarkSword iOS exploit kit active in-the-wild since August 2026. The sample, analyzed in an incident whose exact location was not disclosed, introduces capabilities for crypto wallet data theft, on-device keychain processing, and a remote control panel with over 15 granular commands. The evolution confirms the transformation of leaked commercial toolkits into service platforms for multiple operators, with business models spanning surveillance vendors and financial criminals.
- iVerify documented the P7 DarkSword variant in October 2026, identifying the
p7_prefix in modifications to the original kit code - The implant injects into the iOS SpringBoard process and communicates with C2 infrastructure via polling every 15 seconds, according to the source
- P7 processes keychain data in JSON format directly on the phone, rather than exfiltrating the raw database as in previous variants
- Censys detected open directories on five hosts containing DarkSword and Coruna components, including two real Chinese iOS devices transmitting C2 beacons on September 6, 2026
Exploit Chain and Compatibility Scope
DarkSword exploits two vulnerabilities already patched by Apple: CVE-2025-24201, an out-of-bounds write in the WebKit engine fixed in iOS 18.3.2, and CVE-2025-31200, a memory corruption in the Core Audio framework resolved in iOS 18.4.1. According to official release notes, both CVEs are classified as CRITICAL: the first with a CVSS 3.1 score of 10.0, the second at 9.8. The exploit kit chains them in a sequence that achieves browser sandbox escape and kernel privilege escalation, gaining persistent control of the device.
The P7 variant maintains compatibility with iOS 18.7, the last revision of the branch preceding iOS 26. Apple released iOS 18.7.7 in April 2026 to protect devices that could still install that version. iVerify observed failed attempts to update the framework to iOS 26.x on a separate workspace, likely assisted by large language models: the source does not specify whether these attempts are directly related to the P7 operator or represent parallel development.
Operational Model: From Commercial Kit to Service Platform
DarkSword originated in March 2026, when Google Threat Intelligence Group, iVerify, and Lookout simultaneously documented the toolkit. The source code leak fueled an ecosystem of variants, some with LLM assistance for adaptation to new iOS versions, others with operational professionalization as seen in P7. The variant analyzed by iVerify shows a specific learning curve: reduced detection surface, migration of data processing on-device, enrichment of the C2 protocol.
Censys, an internet scanning platform, identified open directories on five hosts containing DarkSword and Coruna components, a companion module for crypto asset theft. Among the exposed data: 11 victim recovery phrases, 179 stolen data directories, 75 accounts in an admin panel roster. Two real Chinese iOS devices were detected actively polling C2 beacons at three-second intervals on September 6, 2026. Censys researcher Aidan Holland described the platform as a "Chinese-speaking exploitation-as-a-service" operation. The source does not attribute P7 to a specific actor with certainty nor delineate the map of end customers.
"Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure" — iVerify, via The Hacker News
Stealth Techniques and Payload Enrichment
P7 implements three structural modifications compared to previous variants. It eliminates debug logging via HTTP requests and syslog, reducing forensic traces on the device. It uses browser localStorage to mark already-compromised terminals, preventing re-exploitation of the same hardware. It moves keychain processing from remote to on-device: it extracts data in JSON format directly on the phone, rather than copying and transferring the SQLite database to attacker infrastructure. This choice reduces exfiltrated traffic volume and complicates retrospective analysis based on network interceptions.
The implant is injected into the SpringBoard process, the iOS interface manager, which acts as intermediary for all communications with C2 infrastructure. Polling occurs every 15 seconds. Available remote commands exceed fifteen and cover selective exfiltration functions (photos, photo_scan, memo_scan), application reconnaissance (apps, ios_app_data, disk_scan), financial theft (wallet_scan, wallet_extract), file management (download, file_upload) and session control (sleep, exit, execute_command, exec). The wallet_extract command is specific to the imToken app, indicating targeted targeting of Ethereum and compatible wallets.
Immediate Actions
- Update iOS devices to the latest available version: iOS 18.7.7 or later for devices not eligible for iOS 26, which patches CVE-2025-24201 and CVE-2025-31200 exploited by the DarkSword chain
- Monitor network traffic to domains and IPs associated with C2 infrastructure identified by Censys, with attention to regular 15-second polling patterns
- Verify presence of crypto wallet apps on corporate or BYOD devices with access to financial systems, given confirmed targeting of financial sector institution employees
- Analyze SpringBoard logs and process injection traces on unpatched iOS devices showing battery drain or data traffic anomalies
What P7 Means for the Underground Economy
The evolution from original DarkSword to P7 is not incremental: it is a model change. The kit has shifted from a commercial product with defined clientele to shared infrastructure with multiple accounts, victim data aggregated on exposed production servers. The presence of 75 accounts in the Censys admin panel suggests a reseller or subscription model, not monolithic use by a single operator. Failed iOS 26.x porting attempts, though unsuccessful, indicate continued development investment.
The P7 variant also demonstrates that competition among exploit kit operators has shifted from zero-day acquisition to reducing operational footprint and enriching the value of stolen data. On-device crypto wallet theft, with dedicated handlers for specific applications, is more profitable than bulk keychain database exfiltration. The source does not specify transaction volume or value of compromised assets, but the design logic is readable: maximize return per compromise while minimizing visibility.
The P7 DarkSword case signals a saturation point in the commercial iOS exploit market. When a toolkit leaked eight months prior can be re-adapted with enough professionalism to evade standard detection techniques, the barrier to entry for financial criminals and surveillance operators drops structurally. The next variant may not even require that time window.
Frequently Asked Questions
Does P7 DarkSword exploit zero-day vulnerabilities?
No. The exploit chain relies on CVE-2025-24201 and CVE-2025-31200, both already patched by Apple in iOS 18.3.2 and 18.4.1 respectively. The kit's effectiveness depends on unpatched devices.
What is the risk for users on iOS 26?
iVerify has not detected P7 operating on iOS 26.x. The source documents failed porting attempts on a separate workspace, but does not confirm or rule out that future variants may extend support.
Is attribution to Chinese operators certain?
No. Censys detected infrastructure with Chinese-language operations and Chinese iOS devices polling C2, but iVerify does not attribute P7 to a specific actor. The identity of the threat actor behind the variant remains undetermined.
Sources
- https://thehackernews.com/2026/10/p7-darksword-ios-exploit-kit-adds.html
- https://blog.netmanageit.com/p7-darksword-ios-exploit-kit-adds-crypto-wallet-data-theft-and-remote-commands/
- https://cyberinsider.com/new-darksword-iphone-spyware-variant-adds-stealth-and-remote-control/
- https://9to5mac.com/2026/10/08/researchers-uncover-new-darksword-spyware-variant-affecting-unpatched-iphones/
Information verified against cited sources and current as of publication.
Sources
- https://www.rapid7.com/blog/post/etr-cve-2026-21589-critical-unauthenticated-arbitrary-file-access-in-atlassian-products
- https://www.rapid7.com/platform/
- https://www.rapid7.com/products/command/attack-surface-management-asm/
- https://www.rapid7.com/products/command/exposure-management/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.