
Researchers discovered a new DarkSword spyware variant that reduces its footprint on compromised iPhones, processes stolen Keychain data on the device, and gives attackers expanded remote-control capabilities.
Named P7 DarkSword, the variant was identified by iVerify’s Threat Intelligence Team during an August 2026 investigation into an infection on a customer’s device. Its name comes from the p7_ prefix used in modifications to the original code.
The investigation began after an alert differed from the DarkSword detections iVerify typically encounters. With the customer’s consent, researchers collected forensic artifacts, including suspicious files created under /private/var/tmp, and used the Validin platform to locate related exploit and implant samples.
DarkSword was publicly documented in March by Google, Lookout, and iVerify as an iPhone compromise framework chaining six vulnerabilities. Different operators used it against devices running iOS 18.4 through 18.7, with campaigns observed in Ukraine, Saudi Arabia, Turkey, and Malaysia.
iVerify said the August victim was a financial institution employee and that P7 was distributed through malicious ads in watering-hole attacks. The company also said P7 now supports iOS 18.7, compared with the earlier variant it tracked, although other DarkSword deployments already supported that version.
Quieter operation, broader control
P7 reduces its exposure by removing debug logging via HTTP requests and the system log, and by performing fewer process injections. It also uses browser localStorage to prevent repeated exploitation of the same device, improving stability.
The changes do not eliminate all forensic traces. iVerify identified local files associated with Keychain extraction, including keychain_c2_dump.json, a completion marker, and debug files named p7_debug.log and c2_wallet_debug.log.
A significant change concerns how the implant handles Apple Keychain data. Earlier variants copied the Keychain database for processing on attacker infrastructure; P7 extracts the data into a JSON file on the infected phone before exfiltration.
The spyware also supports cryptocurrency wallet discovery and a dedicated handler for extracting data associated with the imToken wallet app. Earlier DarkSword deployments already targeted wallet information, making P7 an evolution of those theft capabilities.
Its command-and-control agent runs inside SpringBoard, the iOS process responsible for the home screen interface. By default, it polls the attackers’ /beacon endpoint every 15 seconds and receives instructions that can change the polling interval or stop the agent.
Supported commands let operators retrieve arbitrary files, upload photos, inventory installed applications, collect Apple Notes databases, extract selected app-container data, and scan the filesystem. The implant can also execute arbitrary JavaScript within its runtime.
iVerify assesses that P7’s authors demonstrated a substantial understanding of the code, distinguishing their modifications from many AI-assisted variants the company has observed.
Apple previously addressed the underlying vulnerabilities and expanded access to DarkSword protections through iOS 18.7.7 in April. Users should install the latest supported iOS release through Settings → General → Software Update and enable automatic updates.






Leave a Reply