Threat Intelligence

New P7 DarkSword iPhone Exploit Kit Variant Steals Crypto Wallet Data and Accepts Remote Commands

The Hacker News · 10 Oct 2026
Key Takeaway Keep staff iPhones updated to the latest iOS version and train your team not to open unexpected links or sign in to Apple ID pages reached through invitations or messages.

Cybersecurity researchers have disclosed a previously unseen variant of the DarkSword iOS exploit kit, named P7 DarkSword. According to iVerify, the variant reduces its on-device footprint, adds theft of keychain and crypto wallet data, and adds two-way communication with the attacker's infrastructure. The name comes from the "p7_" variable prefix the threat actor used when changing the original code.

DarkSword was first publicly documented in March by Google Threat Intelligence Group, iVerify and Lookout. It targets iPhones running iOS 18.4 to 18.7 and was detected in the wild in November 2025. The kit chains multiple iOS vulnerabilities to escape the browser sandbox, gain kernel privileges, and inject its main payload into SpringBoard, the process that handles app launches and the home screen. It is assessed to be a commercial product that ended up in a second-hand market and was then acquired by financially motivated operators and other threat actors.

The kit has been used against targets in Saudi Arabia, Turkey, Malaysia and Ukraine. Reported users include a Turkish commercial surveillance vendor, PARS Defense, which used a fake Snapchat-themed website, and the Russia-aligned group Star Blizzard, which used fake invitation lures. Censys also detailed a campaign by an unknown Chinese-speaking actor that served an Apple ID decoy sign-in page. iVerify says it has seen several unsuccessful, likely LLM-assisted attempts to update the kit for iOS 26.x, following its leak. These variants focus on stability, stealth and the quality of stolen data.

iOS DarkSword exploit kit mobile security crypto wallet theft

Summarised by CISO AI from The Hacker News, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.