Researchers uncover new DarkSword spyware variant affecting unpatched iPhones
iVerify said the malware now steals Keychain and crypto-wallet data on-device while reducing its footprint and giving attackers more control.
- On Thursday, mobile security company iVerify released a report detailing P7 DarkSword, a new spyware variant discovered on a financial institution employee's iPhone that steals Keychain data and crypto-wallet information.
- The operators distribute P7 through watering-hole attacks and malicious advertising, meaning victims encounter the threat via compromised web content rather than individual targeting.
- P7 improves stealth and stability with two-way command-and-control communication, allowing attackers to extract Keychain data, access Apple Notes databases, and scan the device filesystem.
- Apple released security updates for affected devices, including iOS 18.7.7, though users running outdated system versions remain the primary targets for DarkSword attacks.
- Functional upgrades appear to reflect substantial work by the operators, allowing P7 to reduce on-device logging and hide more effectively than earlier variants.
15 Articles
15 Articles
New DarkSword Spyware Variant Targets Unpatched iPhones via Zero-Click WebKit Exploits
Researchers have uncovered a stealthier new variant of DarkSword spyware that targets unpatched iPhones using zero-click WebKit exploits, enhanced data theft, and obfuscation techniques. The malware primarily affects outdated iOS devices, underscoring the critical need for timely software updates.
Unpatched iPhones Are Being Targeted by P7 DarkSword Spyware Built for 'Crypto-Wallet Theft'
Researchers say a new P7 DarkSword spyware variant is targeting unpatched iPhones, with capabilities including Keychain extraction, crypto-wallet searches and remote theft of files, photos and notes.
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware - National Cyber Security Consulting
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. […] Thank you for subscribing to our RSS feed!
iVerify has published a report on P7 DarkSword, a new variant of the malware from the iPhone exploit chain DarkSword. Such chains combine multiple iOS loops to make devices with outdated devices...To post: P7 DarkSword: New variant of iPhone spyware camouflages better Where to follow us: Facebook, Reddit, Google News, X, Threads Stay up to date? Adds us to Google as a preferred source!
Coverage Details
Bias Distribution
- 67% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium












