
DarkSword variant gives attackers remote control of iPhones
DarkSword’s P7 variant steals wallet and keychain data and accepts remote commands on compromised iPhones, according to research published by iVerify.
DarkSword has a newly documented variant that lets attackers issue commands to compromised iPhones and extract cryptocurrency wallet data and stored credentials, according to mobile security company iVerify. Called P7 DarkSword, it also processes stolen keychain information on the phone and removes some diagnostic activity that could leave traces of the infection.
The name comes from the p7_ prefix added to variable names in the modified code. Google Threat Intelligence Group (GTIG), iVerify and Lookout publicly documented the original DarkSword in March, after its detection in attacks in November 2025. That research described targeting of iPhones running iOS 18.4 through 18.7. Those historical targeting ranges should not be read as proof that every release in the range remains vulnerable to every variant.
DarkSword is an exploit kit, a collection of code that takes advantage of software flaws. It links several iOS vulnerabilities to escape the browser sandbox, the boundary intended to isolate web content, and gain kernel privileges, control at the operating system’s core. It then inserts its main malicious component into SpringBoard, the iOS process responsible for the home screen and application launches. Researchers assess that the kit began as a commercial product before reaching a secondary market and multiple operators from late 2025.
P7 removes debug logging, diagnostic records previously sent through web requests and the system logging facility. It also uses localStorage, storage available to websites inside a browser, to avoid exploiting the same device again. Earlier variants copied the keychain database, which stores sensitive credentials, for processing on attacker systems. P7 instead extracts the information on the phone into JSON, a structured text format, before sending it out. These are specific changes in how the malware operates, not evidence that it leaves no detectable traces.
According to iVerify, the implant inside SpringBoard handles communication with the attackers’ command-and-control (C2) infrastructure, the systems that direct the infection and receive stolen information. It checks for instructions every 15 seconds, sends a heartbeat to indicate that it is active, and can transmit an installed-app list, iCloud Keychain information, Apple Notes, photos and cryptocurrency wallet data. This two-way connection lets an operator request further actions rather than simply collect a predetermined set of files.
The command set includes execute_command for operating-system commands, ls for directory listings, and download for reading a device file and uploading it to the attacker. The exec instruction runs arbitrary JavaScript, programming code, inside the implant. Other instructions search folders and upload matching files, collect device details, inventory files and directories, enumerate application containers and retrieve selected app data. Application containers are the storage areas assigned to individual apps. The wallet_scan command looks for wallet apps, while wallet_extract targets data belonging to imToken. Separate commands collect Apple Notes databases and Apple Photos files; photos accesses /var/mobile/Media/DCIM. Operators can change the contact interval with sleep or stop the implant with exit.
Attempts to extend DarkSword to newer devices remain a separate issue. iVerify reported observing multiple unsuccessful efforts to add iOS 26.x support, which it considered likely to have used large language models, the technology behind many AI coding tools. It linked the broader wave of modifications to the kit’s leak shortly after public disclosure. The variants it observed emphasised reliability, concealment and the quality of stolen information. Unsuccessful development attempts do not establish working support for iOS 26.x.
Separately, internet-exposure research company Censys identified five hosts with open directories, publicly accessible file listings, containing DarkSword and Coruna components. Coruna is another iOS exploit kit, previously described in attacks against iOS 13.0 through 17.2.1. Censys says operators also distribute it alongside DarkSword, with browser-session components that harvest cryptocurrency recovery phrases, balances and keystore data, files holding wallet key information. A recovery phrase can give someone control of a cryptocurrency wallet, making its exposure particularly consequential.
Censys found a combined DarkSword and Coruna package called DS-Fusion v1.0, also known as DarkSword Fusion, at 43.134.165[.]205. A command server at 166.88.95[.]90 recorded two real iOS devices in China checking a beacon page every three seconds for several hours on September 6, 2026. Another host, 23.148.212[.]237, exposed an analysis workspace showing work on iOS 26 exploit chains, including CVE-2026-31001, outside the coverage of DarkSword and Coruna. The researchers identified 47.102.192[.]23 as a Coruna staging host and 156.239.230[.]120 as an exposed C2 platform observed polling a device on September 15, 2026.
The production server’s exploit registry also listed two vulnerabilities not previously documented as part of DarkSword. CVE-2025-24201 is an out-of-bounds write in WebKit, Apple’s browser engine, which can let malicious code cross the web-content sandbox boundary. It was fixed in iOS 18.3.2 and iPadOS 18.3.2. CVE-2025-31200 is a memory-corruption flaw in Core Audio that permits code execution when a specially crafted audio stream is processed. Its fixes arrived in iOS 18.4.1 and iPadOS 18.4.1. These are fixes for individual flaws, not a stated all-purpose remedy for every toolkit combination described in the research.
Censys suspects a Chinese-speaking operator runs the exposed directory cluster and platform to steal cryptocurrency wallet information, but the operator’s identity is unknown. Researcher Aidan Holland described an exploitation service with agents and resellers. A recovered production-server copy contained 11 victim recovery phrases, 179 device loot directories and a 75-account administrative roster. These are distinct measurements and should not be combined into a victim total. Censys also found a separate China-based operator using 66ds[.]lol as its command server and adding BitKeep as a wallet target. It linked that operator’s Tencent and Shenyang hosting through a unique self-signed certificate authority, a system used to issue digital identity certificates.
For website owners and businesses, this is a mobile-device security issue rather than a reported flaw in hosting or WordPress: phones can hold credentials and business information alongside personal data. AEU-I’s security-first IT, infrastructure and consulting services are relevant to businesses reviewing device security, without implying a DarkSword-specific detection or protection capability.
Si të Mbroheni
- On your iPhone, open Settings, General, Software Update and install the newest update offered for your device.
- In Software Update, open Automatic Updates and enable automatic installation of iOS updates.
- Open account sign-in pages through Settings or an address you already trust, rather than through an unexpected message link.
- Keep cryptocurrency recovery phrases out of Apple Notes and Photos; use an offline backup stored somewhere physically secure.
- If you suspect your phone has been compromised, contact your IT team and change important account passwords from a different, trusted device.
Dobësitë & Zgjidhjet
- CVE-2025-24201 A WebKit out-of-bounds write allowing web-content sandbox escape was fixed in iOS 18.3.2 and iPadOS 18.3.2. Shiko zgjidhjen & detajet →
- CVE-2025-31200 A Core Audio memory-corruption flaw allowing code execution through crafted audio was fixed in iOS 18.4.1 and iPadOS 18.4.1. Shiko zgjidhjen & detajet →
- CVE-2026-31001 Censys observed this identifier in work on iOS 26 exploit chains; the supplied report provides no flaw details or fix. Shiko zgjidhjen & detajet →
Termat e Shpjeguar
- exploit kit A collection of attack code designed to take advantage of software weaknesses.
- browser sandbox A protective boundary meant to prevent website content from accessing the rest of a device.
- keychain Apple’s storage system for passwords and other sensitive account information.
- command-and-control (C2) Attacker-operated systems that send instructions to infected devices and receive stolen data.
- localStorage A browser feature that lets a website save information on a device between visits.
- recovery phrase A set of secret words that can restore access to a cryptocurrency wallet.