DarkSword’s P7 Variant Supercharges iOS Exploits with Wallet Theft & Remote Control

A fresh variant of the DarkSword iOS exploit kit, dubbed “P7 DarkSword,” has emerged with significant upgrades that pose a renewed threat to iPhone users. Security analysts have uncovered that this next-gen tool adds direct crypto-wallet theft, remote command-and-control (C2) capabilities, and enhanced stealth features. These changes tighten DarkSword’s grip on device data and resilience, and lower its visibility.

What’s New in P7 DarkSword

Former versions of DarkSword had already caused concern with their ability to escape the browser sandbox, gain kernel-level privileges, and embed a payload in SpringBoard — the iOS process responsible for handling app launches and the home screen. But the P7 version takes things further. It reduces its on-device footprint, drops debug logging over HTTP and syslog, and relies on browser localStorage for persistence, rather than older, more detectable methods. It even formats keychain data into JSON before exfiltrating it directly from the device. All these tweaks make P7 stealthier and more evasive. These findings are drawn from a recent report by iVerify released on October 9, 2026.

Expanded Commands & Data Theft

P7 DarkSword now performs continuous back-and-forth communication with attacker-controlled infrastructure. Every 15 seconds, the implant checks in by sending a “heartbeat,” while also reporting app usage, installed apps, device metadata, iCloud Keychain info, and data from apps like Notes, Photos, along with crypto wallets. Once inside, operators can execute nearly two dozen command types via the implant—ranging from directory listings and file downloads to executing system commands (including listing running processes, memory dumps), scanning for installed wallet apps, extracting wallet data (especially from imToken), uploading photos, reading Apple Notes, and performing disk-wide scans. These abilities make P7 a far more versatile surveillance and data-exfiltration tool than its predecessors.

Where It’s Targeting & Ecosystem Links

DarkSword was first documented publicly in March 2026, with active exploitation traced back to November 2025, targeting iPhones running iOS versions between 18.4 and 18.7. A broader component named Coruna works in tandem with DarkSword—once exploit stages succeed, Coruna handles browser-based payloads to harvest wallet recovery phrases, balances, and keystore files from crypto apps. Together, they form a powerful offensive ecosystem. Notably, attacks have been launched in Saudi Arabia, Turkey, Malaysia, Ukraine, with known involvement by a Turkish surveillance vendor using fake Snapchat-themed sites, and a Russia-aligned group called Star Blizzard using invitation lures.

CVE Vulnerabilities Behind the Exploit

P7 DarkSword hinges on multiple previously unknown vulnerabilities to gain full control. Two new CVEs—CVE-2025-24201 (an out-of-bounds write vulnerability in WebKit) and CVE-2025-31200 (a memory corruption flaw in Core Audio)—are at its core. Both have since been patched in iOS versions 18.3.2 and 18.4.1 respectively, but devices running those or older unrevised versions remain at risk.

The hostile infrastructure behind these tools appears to be spread across multiple open directories and servers. Researchers identified several hosts serving different pieces—some stage payloads, others act as C2 servers, analysis workspaces, or staging platforms. One major cluster seems linked to a Chinese-speaking threat actor using an ‘agent/reseller’ model to distribute DarkSword as an “exploitation-as-a-service” tool. Among the loot recovered: statements that point to thousands of stolen credentials, hundreds of exploited devices, and several recovered wallet phrases. One operator was even seen targeting a new wallet app, BitKeep, not previously in DarkSword’s scope.

Major actors using DarkSword include PARS Defense (Turkey), Star Blizzard (Russia-aligned), and unknown Chinese-language groups. Tactics include impersonating Apple-ID pages or using decoy wallets and invitation lures to trick victims. The attack chain is complex—chain of vulnerabilities, sandbox escape, kernel compromise, and implant of persistent remote control. All that enables extraction of keychain, crypto data, photos, app info—and much more.

Devices running patched iOS versions (at least 18.4.1 for the Core Audio issue, and 18.3.2 for WebKit) are protected from these specific vulnerabilities—but unpatched devices remain in grave danger. Security vendors are warning users to update immediately. Monitoring of C2 infrastructure shows some servers exposed, others well-hidden; threat actors are actively updating exploit tools and seeking to expand coverage to newer iOS releases, possibly including iOS 26.x.

While many may dismiss zero-day exploits and sophisticated iPhone malware as remote concerns, P7 DarkSword is already here, active, and preying where users are most exposed—that is, on outdated devices or insecure networks. The fact that crypto wallet data is now squarely in its crosshairs elevates the stakes. Going forward, watch for how Apple responds—patches beyond the identified CVEs, systemic fixes in iCloud and wallet apps—and whether exposure of C2 infrastructure forces threat actors to change tactics. Vendors developing wallet and keychain software should also harden local data storage and assume remote access attempts as a given.