P7 DarkSword iOS exploit activity has evolved with a newly documented variant that adds on-device keychain extraction, cryptocurrency-wallet theft, Photos and Notes collection, and two-way command-and-control capabilities.
iVerify Threat Intelligence researchers discovered the previously unseen variant during an August 2026 investigation into a DarkSword infection on a customer device.
The researchers named it P7 DarkSword because the threat actor used the p7_ variable prefix in modifications made to the original DarkSword code.
Compared with earlier variants, P7 DarkSword reduces its on-device footprint, removes some debug logging, improves stability and gives operators significantly more control over infected iPhones.
For broader coverage of advanced mobile exploitation, see our Zero-Click and Device Exploits Security Hub.
Key takeaway: P7 DarkSword does more than steal static device data. It can beacon to attacker infrastructure, receive commands, scan wallets, extract app data, collect Photos and Notes, and upload selected files from a compromised iPhone.
What Is P7 DarkSword?
P7 DarkSword is a new variant of the DarkSword iOS exploit and implant ecosystem first publicly documented earlier in 2026.
DarkSword is a full-chain iOS exploitation framework capable of escaping the browser sandbox, escalating privileges and injecting an implant into SpringBoard, the iOS process responsible for the home screen and application launching.
The original DarkSword activity was linked to multiple threat actors and commercial surveillance use, but the newly analyzed P7 variant focuses heavily on stealth, stability and the quality of stolen data.
P7 DarkSword Improves Stealth and Stability
iVerify says P7 improves on previous DarkSword variants in three main areas.
- Stealth: It removes debug logging over HTTP and syslog and reduces the number of process injections.
- Stability: It uses browser localStorage to prevent repeated exploitation of the same device.
- Functionality: It performs on-device keychain extraction and adds advanced two-way C2 communication.
Earlier DarkSword variants copied the keychain database and processed it on attacker infrastructure.
P7 instead extracts keychain information into JSON directly on the compromised iPhone before sending the data to the attacker.
Implant Runs Inside SpringBoard
The P7 implant is injected into the SpringBoard process.
That process then becomes the central communication point between the compromised iPhone and attacker-controlled command-and-control infrastructure.
According to iVerify, the implant regularly sends requests to several endpoints for:
- Tasking
- File exfiltration
- Device registration
- Heartbeat messages
- Installed application inventory
- Apple Notes collection
- Photo theft
- Keychain and wallet data
P7 Polls for Commands Every 15 Seconds
The core command channel uses a /beacon request.
By default, the compromised device polls the attacker infrastructure every 15 seconds.
The attacker can change that interval remotely using the malware’s sleep command.
Responses to beacon requests contain instructions that the implant executes directly on the victim’s phone.
Remote Commands Give Attackers Extensive Control
P7 DarkSword includes a broad command set for exploring and manipulating the compromised device.
The implant can perform operations including:
- Listing directories
- Reading files
- Creating and deleting files or directories
- Moving and copying files
- Enumerating processes
- Collecting device and network information
- Running arbitrary JavaScript
- Uploading selected files
- Scanning the filesystem
- Extracting application sandbox data
The combination makes P7 closer to an interactive remote surveillance implant than a simple one-time information stealer.
Crypto Wallet Apps Are Directly Targeted
One of the most important additions is dedicated cryptocurrency-wallet functionality.
P7 includes commands to:
- Scan the device for installed wallet applications
- Identify wallet-related app containers
- Extract wallet-specific data
iVerify specifically documented functionality for extracting information associated with the imToken wallet app.
Separate Censys research into the broader DarkSword and Coruna ecosystem found a much larger wallet-theft operation targeting numerous cryptocurrency wallets. :chatgpt-content-reference{index=”1″}
Censys Found 18 Wallet-Theft Modules
Censys researchers discovered exposed DarkSword and Coruna infrastructure containing 18 wallet-targeting modules.
Each module was designed to target a specific cryptocurrency wallet application.
The platform also searched Apple Photos and Notes for BIP39 recovery phrases that could give attackers control over cryptocurrency assets. :chatgpt-content-reference{index=”2″}
A separate operator was observed using the same framework with BitKeep as a nineteenth wallet target. :chatgpt-content-reference{index=”3″}
Real Wallet Recovery Phrases Were Found on Attacker Infrastructure
Censys recovered evidence showing the ecosystem was not purely experimental.
A production server contained:
- 11 victim cryptocurrency recovery phrases
- 179 device loot directories
- 87-plus on-chain addresses
- A 75-account control-plane roster
The recovered recovery phrases were associated with wallets including TronLink, Bitget, Bitpie, Trust, Phantom and imToken. :chatgpt-content-reference{index=”4″}
These numbers relate to the exposed DarkSword/Coruna platform studied by Censys and should not be interpreted as the total number of P7 DarkSword victims.
P7 Can Steal Apple Notes
The malware includes dedicated functionality for locating and uploading Apple Notes databases.
Researchers documented temporary files corresponding to:
NoteStore.sqlitenotes.sqlite- Associated WAL and shared-memory files
Notes may contain highly sensitive information such as passwords, account recovery information, personal data or cryptocurrency recovery phrases.
P7 Can Upload Photos From the iPhone
The implant can access Apple’s Photos storage and upload files from the device.
One command walks the /var/mobile/Media/DCIM directory and transfers photo files to the command server.
Another command queries the Photos database for recent images, computes hashes and uploads selected files.
This gives an attacker the ability to selectively collect media rather than simply dumping the entire device.
Installed Apps Can Be Enumerated
P7 can enumerate application containers and extract bundle identifiers for installed apps.
This information allows operators to understand what applications are installed on the compromised phone and decide what data may be worth collecting.
For targeted surveillance or cryptocurrency theft, knowing whether a specific wallet, messaging application or financial app is installed can significantly improve attack efficiency.
P7 Can Scan the Entire Filesystem
The disk_scan command recursively walks the filesystem starting from the root directory.
It records metadata for files, directories and symbolic links, creates a report and uploads that information to the command server.
This gives operators a map of the device before choosing which files to extract.
Why P7 Is Different From Earlier DarkSword Variants
The important change is not simply that P7 steals more data.
Earlier variants were more heavily focused on exploitation and bulk exfiltration.
P7 moves toward a more interactive model where the attacker can repeatedly task the device after compromise.
That allows operators to adapt their actions based on:
- Installed applications
- Available wallet software
- Files found on the device
- User activity
- Previously collected data
DarkSword Source Code Leak Fueled New Variants
iVerify says DarkSword’s source code was leaked by a third party after the exploit chain was publicly disclosed earlier in 2026.
Because much of the framework is written in JavaScript, attackers can relatively easily modify and repurpose the code.
Since the leak, researchers have observed multiple variant clusters focused on improving:
- Exploit reliability
- Stealth
- Stolen-data quality
- Payload stability
iVerify also observed multiple unsuccessful attempts that appeared likely to be assisted by large language models and aimed at extending DarkSword to iOS 26.x. :chatgpt-content-reference{index=”5″}
iOS 26 Exploitation Is Still Under Development
Censys independently found evidence that operators were developing an additional exploit path targeting iOS 26.
The research identified work involving CVE-2026-31001, described as a JavaScriptCore type-confusion issue.
However, the iOS 26 chain was still under development and had not been deployed in the observed production attacks.
Censys specifically cautioned that this should not be described as an active zero-day attack. :chatgpt-content-reference{index=”6″}
DarkSword Has Been Used by Multiple Threat Actors
Google Threat Intelligence Group previously found DarkSword being used by multiple actors since late 2025.
Observed activity included commercial surveillance vendors, financially motivated operators and suspected state-linked actors.
Targets have appeared in countries including:
- Saudi Arabia
- Turkey
- Malaysia
- Ukraine
Google assessed that DarkSword likely originated as a commercial exploit product that later spread through a secondary market. :chatgpt-content-reference{index=”7″}
Original DarkSword Used Six iOS Vulnerabilities
The original exploit chain documented by Google used six vulnerabilities across multiple parts of iOS.
The chain was capable of moving from browser exploitation to full device compromise.
Google reported the flaws to Apple, and the vulnerabilities used by the documented chain were patched by the release of iOS 26.3, with most receiving fixes earlier. :chatgpt-content-reference{index=”8″}
Updating iOS Remains the Most Important Defense
Users should keep iPhones updated to the newest iOS release supported by their device.
Older DarkSword chains relied on vulnerabilities that Apple has already patched.
Installing security updates reduces the number of known exploit paths available to operators using leaked or repurposed exploit frameworks.
High-Risk Users Should Consider Lockdown Mode
Google has recommended enabling Lockdown Mode when users cannot immediately update or when they face elevated targeting risk.
Lockdown Mode reduces parts of the iPhone attack surface and is designed specifically for users who may be targeted by sophisticated spyware or mercenary surveillance campaigns.
Journalists, government personnel, political figures, activists, cryptocurrency executives and other high-risk individuals may benefit from reviewing whether Lockdown Mode is appropriate for their situation.
What iPhone Users Should Do
- Install the latest available iOS update.
- Avoid delaying security updates on high-risk devices.
- Enable Lockdown Mode if you face elevated targeted-attack risk.
- Treat unexpected links and invitation pages cautiously.
- Do not store cryptocurrency recovery phrases in Photos or Notes.
- Use hardware wallets for significant cryptocurrency holdings where practical.
- Investigate unexpected device behavior or mobile-security alerts.
Why Storing Recovery Phrases in Photos or Notes Is Risky
The DarkSword ecosystem demonstrates why recovery phrases should not be stored in locations accessible to a fully compromised phone.
If an attacker gains high-level access to the device, screenshots, Notes databases and wallet app storage can all become potential sources of cryptocurrency secrets.
Offline storage methods reduce exposure to device-level malware.
Frequently Asked Questions
What is P7 DarkSword?
P7 DarkSword is a newly analyzed variant of the DarkSword iOS exploit and implant framework that adds stronger stealth, on-device keychain theft, crypto-wallet targeting and interactive command-and-control functionality.
Why is it called P7?
iVerify named the variant after the p7_ variable prefix used by its developers in modifications to the original DarkSword code.
What can P7 DarkSword steal?
It can collect keychain information, wallet-related data, Apple Notes, Photos, installed-app information, selected files and other device metadata.
Can attackers remotely control an infected iPhone?
The implant supports two-way command-and-control and can receive commands for file access, device reconnaissance, uploads, app-data extraction and arbitrary JavaScript execution.
Does P7 target cryptocurrency wallets?
Yes. iVerify documented dedicated wallet-scan and wallet-extraction functionality, including support for extracting imToken-related data.
Is iOS 26 currently vulnerable to DarkSword?
Researchers found attempts and development work aimed at iOS 26, but the observed iOS 26 chain was not deployed and should not be described as an active zero-day.
How can users protect themselves?
Keep iOS fully updated, consider Lockdown Mode for high-risk users, avoid suspicious links and do not store cryptocurrency recovery phrases in Photos or Notes.
Final Takeaway
The new P7 DarkSword iOS exploit variant shows how quickly leaked mobile exploitation frameworks can evolve after entering the wider threat ecosystem.
P7 improves stealth and stability while adding interactive remote commands, on-device keychain processing, wallet scanning, Photos and Notes theft and selective file exfiltration.
Separate research also shows that the wider DarkSword/Coruna ecosystem is being commercialized for cryptocurrency theft, with real wallet recovery phrases and victim data recovered from attacker infrastructure.
For iPhone users, especially those handling cryptocurrency or facing elevated surveillance risks, staying fully patched and keeping recovery phrases off the device remains critical.
Stay Updated on Mobile Security
Mobile exploit kits are becoming increasingly reusable, commercialized and accessible to multiple threat actors.
Follow CyberUpdates365 for verified mobile security news, iOS exploit research, spyware analysis, vulnerability updates and practical device-protection guidance.
Primary Sources
iVerify Threat Intelligence:
Sleep, Beacon, Steal, Repeat — The Story of P7 DarkSword Variant
Censys Research:
DarkSword/Coruna Open Directory Finding Report
Google Threat Intelligence Group:
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors




