New P7 DarkSword iPhone Exploit Kit Variant Steals Crypto Wallet Data and Accepts Remote Commands
Cybersecurity researchers have disclosed a previously unseen variant of the DarkSword iOS exploit kit, named P7 DarkSword. According to iVerify, the variant reduces its on-device footprint, adds theft of keychain and crypto wallet data, and adds two-way communication with the attacker's infrastructure. The name comes from the "p7_" variable prefix the threat actor used when changing the original code.
DarkSword was first publicly documented in March by Google Threat Intelligence Group, iVerify and Lookout. It targets iPhones running iOS 18.4 to 18.7 and was detected in the wild in November 2025. The kit chains multiple iOS vulnerabilities to escape the browser sandbox, gain kernel privileges, and inject its main payload into SpringBoard, the process that handles app launches and the home screen. It is assessed to be a commercial product that ended up in a second-hand market and was then acquired by financially motivated operators and other threat actors.
The kit has been used against targets in Saudi Arabia, Turkey, Malaysia and Ukraine. Reported users include a Turkish commercial surveillance vendor, PARS Defense, which used a fake Snapchat-themed website, and the Russia-aligned group Star Blizzard, which used fake invitation lures. Censys also detailed a campaign by an unknown Chinese-speaking actor that served an Apple ID decoy sign-in page. iVerify says it has seen several unsuccessful, likely LLM-assisted attempts to update the kit for iOS 26.x, following its leak. These variants focus on stability, stealth and the quality of stolen data.