Cybersecurity researchers have disclosed comprehensive technical details regarding a previously unseen variant of the sophisticated DarkSword iOS exploit kit, which has been identified as P7 DarkSword. This latest evolution introduces a reduced on-device footprint, specialized capabilities for stealing local keychains and cryptocurrency wallets, and full two-way command-and-control (C2) communication capabilities that connect directly back to malicious actor infrastructure.
In a newly published threat research report, mobile security firm iVerify detailed how this variant diverges from previously observed iterations. According to the researchers, the designation "P7" serves as a direct nod to the threat actor’s distinct naming convention, specifically their use of the "p7_" variable prefix introduced into modifications made directly to the foundational DarkSword source code.
The original DarkSword toolkit was first brought to public attention in March by the Google Threat Intelligence Group (GTIG), alongside iVerify and Lookout. Initial documentation revealed that the exploit kit was engineered to target iPhones running specific iOS versions ranging between iOS 18.4 and iOS 18.7, having been actively detected in the wild as early as November 2025.
Engineered as a multi-stage mechanism, the toolkit is capable of chaining multiple underlying iOS vulnerabilities to successfully escape the tight constraints of the Safari browser sandbox. Once sandbox escape is achieved, the kit escalates its execution privileges up to the kernel level, ultimately injecting its primary payload directly into SpringBoard—the core iOS system process responsible for managing application launches and rendering the user home screen. Security analysts assess that the exploit chain originated as a commercial surveillance product that somehow leaked into the secondary market, where it was subsequently acquired by financially motivated operators and various state-sponsored threat actors starting in late 2025.

Since its public exposure, the exploit kit has been heavily leveraged in targeted campaigns across multiple geographic regions, including Saudi Arabia, Turkey, Malaysia, and Ukraine. Various threat actors have integrated the toolkit into their operations, such as a Turkish commercial surveillance vendor known as PARS Defense, which utilized a fake Snapchat-themed website as a delivery vector. Concurrently, a Russia-aligned threat actor tracked as Star Blizzard, also referred to as COLDRIVER, deployed the kit using deceptive invitation lures.
The proliferation of the exploit kit continued to expand when attack surface management platform Censys detailed a campaign orchestrated by an unknown Chinese-speaking threat actor. This campaign targeted Apple iOS devices using the exploit kit while simultaneously serving a fraudulent Apple ID decoy sign-in page to capture user credentials.
As recently as last month, iVerify reported observing multiple unsuccessful, likely large language model (LLM)-assisted attempts by various malicious actors to update the framework so that it could provide support for newer iOS versions, specifically iOS 26.x. These experimental variants were fueled by the widespread leak of the exploit kit shortly after its initial public disclosure. Mobile security experts noted that these subsequent iterations were primarily focused on improving execution stability, enhancing operational stealth, and increasing the overall quality and quantity of data stolen from compromised devices.
In some rare instances, iVerify noted that DarkSword and another related toolkit known as Coruna had been bundled together, a combined deployment trend referred to by researchers as DarkCoruna. Investigators determined that these threat actors had obtained the source code for the Coruna exploit kit and modified it directly, pointing out that there were no signs of binary patching involved. Instead, substantial code changes were executed from scratch and successfully compiled into entirely new operational binaries.
While many bundled variants observed by researchers amounted to non-sophisticated, broken attempts—often described as AI-generated slop deployed by low-skill attackers pulling patched codebases from GitHub—experts emphasize that the threat landscape continues to evolve rapidly. Security teams cannot rule out the possibility that attackers who lack direct access to the Coruna source code might ultimately reverse-engineer and re-implement its features with the assistance of advanced artificial intelligence models, even though direct evidence of this specific capability remains limited for now.

The newly documented P7 DarkSword variant represents a significant qualitative leap in capability by eliminating debug logging over HTTP requests and system logs, while additionally leveraging browser localStorage mechanisms to prevent redundant re-exploitation attempts. Unlike older variants that simply copied and exfiltrated the entire keychain database to process on external attacker infrastructure, this updated version extracts and parses keychain data into structured JSON format directly on the victim’s phone prior to exfiltration.
The implant is injected directly into the SpringBoard process, which subsequently handles all active communication channels with the attacker’s infrastructure. This latest iteration is fully equipped to poll for new commands every 15 seconds, transmit regular heartbeat verification messages, compile and transmit a complete list of installed applications, and siphon sensitive data from iCloud Keychain alongside information from native and third-party applications such as Apple Notes, Photos, and various cryptocurrency wallets.
The operational response received during these periodic tasking polls contains dynamic commands slated for immediate execution on the victim’s phone. Interestingly, instances of the P7 DarkSword exploit have also been distributed through web infrastructure previously associated with a now-defunct Czech e-commerce analytics startup. According to analysis from Report URI, unknown threat actors successfully re-registered the domain "ecomtrack.io" following its formal expiration, using it to inject malicious JavaScript into web store environments that still featured lingering tracking tags referencing the old analytics service.
Security researcher Scott Helme noted that because these tags remained active on various online stores, the compromised domain began automatically hijacking incoming visitors, monetizing traffic through external ad networks, and in specific targeted instances, delivering a full iOS exploit chain and sophisticated spyware implant. The underlying JavaScript payload incorporates advanced evasive checks designed to detect automated web crawlers, headless browsers, and security analysis bots, employing active cloaking tactics to serve empty content and mask its malicious intent.
The script gathers comprehensive information about the visitor’s device and browser environment, relays these details to an external collection server, and subsequently redirects the unsuspecting user to various scam websites or fraudulent online gambling platforms. One identified routing path leads directly to a bogus cryptocurrency trading platform operating under the domain "chainmate.top," which stealthily serves the DarkSword iOS exploit chain. The resulting implant is explicitly engineered to capture a vast array of sensitive personal data, including SMS messages, contact lists, call histories, voicemails, photos, Apple Health records, location histories, device notifications, saved Wi-Fi network passwords, and data files associated with more than 25 distinct cryptocurrency wallet applications.

Code recovered from these secondary distribution channels has been configured to maintain regular contact with a C2 server at "mertio.cc" at 30-second intervals, handling specialized execution commands such as file execution, data downloading, photo extraction, and active surveillance. Security analysts point out that this particular build appears to be a newer version, designated as v24, which reports to entirely different backend infrastructure and targets a significantly broader array of digital asset wallets.
This latest disclosure coincides with findings from Censys, which successfully identified open directories hosted across five distinct servers containing operational components tied to both DarkSword and Coruna. Coruna functions as a companion payload kit distributed within the same overarching cybercriminal ecosystem. Its operational stages execute directly inside the victim’s active browser session immediately after the initial DarkSword exploit stages successfully land on the device, deploying dedicated wallet-harvesting modules designed to steal cryptocurrency recovery phrases, account balances, and keystore data directly from installed iOS applications. Threat operators routinely run DarkSword and Coruna in tandem, directing data flows back to their own unified C2 infrastructure.
An exhaustive technical analysis of the production server’s exploit registry revealed that the underlying DarkSword exploit kit incorporates multiple vulnerabilities, including CVE identifiers that had not been previously documented in public threat intelligence feeds. Security researchers strongly suspect that this open-directory cluster and an associated exploitation platform hosted at an IP address linked to 156.239.230.120 are operated by a Chinese-speaking threat actor whose primary objective is large-scale cryptocurrency wallet theft, though the exact identity of the individuals behind the operation remains undetermined.
According to Censys researcher Aidan Holland, the underlying platform operates essentially as a Chinese-speaking exploitation-as-a-service enterprise. The administrative control panel exposes a formalized agent and reseller model, and a forensic copy of the recovered production server contained a substantial volume of stolen material, including 11 distinct victim recovery phrases, 179 device loot directories, and an active control-plane roster comprising 75 separate accounts.
Furthermore, Censys detected a separate China-based operator actively deploying the exact same exploit kit in the wild against its own dedicated C2 server located at "66ds.lol," while simultaneously incorporating a new cryptocurrency wallet target, specifically BitKeep, which was noticeably absent from the previously analyzed open-directory set. These cumulative findings underscore the ongoing, widespread proliferation and commercialization of sophisticated mobile exploit kits among financially motivated threat groups operating across the global digital landscape.
