New Variant of DarkSword iOS Exploit Kit Surfaces with Advanced Crypto-Theft and Two-Way C2 Capabilities

Cybersecurity researchers have disclosed technical details regarding a previously undocumented and highly sophisticated variant of the DarkSword iOS exploit kit, which has been designated by analysts as P7 DarkSword.

According to a comprehensive threat research report published by mobile security firm iVerify, the newly uncovered iteration introduces several significant modifications compared to older versions of the toolkit. Most notably, P7 reduces its on-device footprint, introduces native capabilities for stealing device keychains and cryptocurrency wallets, and establishes a robust two-way command-and-control (C2) communication channel with the attacker’s external infrastructure.

The name "P7" was coined by researchers as a direct nod to the threat actor’s distinct use of the "p7_" variable prefix discovered within code modifications made to the original DarkSword framework. The emergence of P7 DarkSword marks the latest chapter in the evolution of a commercial-grade mobile exploitation tool that has increasingly found its way into the hands of a diverse array of threat actors since its initial leak.

The Evolution and Proliferation of the DarkSword Ecosystem

The DarkSword exploit kit was first publicly documented in March 2026 by a collective of security organizations, including the Google Threat Intelligence Group (GTIG), iVerify, and Lookout. Initial disclosures detailed the toolkit’s powerful capability to target iPhones running modern iOS versions, specifically focusing on software builds ranging between iOS 18.4 and iOS 18.7. Telemetry data indicated that the kit had been actively detected in the wild as early as November 2025.

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Engineered with advanced technical precision, the toolkit is designed to chain multiple iOS vulnerabilities together in a rapid sequence. This multi-stage process successfully escapes the strict confines of the mobile browser sandbox, escalates privileges to the kernel level, and ultimately injects the primary payload directly into SpringBoard—the core iOS process responsible for managing application launches and the graphical home screen. Security analysts assess that the exploit chain originated as a commercial surveillance product. Somehow, the source code leaked or escaped into the secondary market, where it was rapidly acquired by financially motivated cybercriminals, state-sponsored groups, and commercial spyware vendors starting in late 2025.

Over the past year, the exploit kit has been linked to various targeted campaigns across the globe, including operations affecting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Notable operators identified by researchers include a Turkish commercial surveillance vendor known as PARS Defense, which deployed the kit via fake Snapchat-themed websites, and a Russia-aligned threat actor tracked as Star Blizzard (also known as COLDRIVER), which utilized fake invitation lures to ensnare targets. Furthermore, in August 2026, attack surface management platform Censys detailed a separate campaign mounted by an unknown Chinese-speaking threat actor that leveraged the exploit kit alongside deceptive Apple ID sign-in pages to harvest credentials.

Under the Hood of P7 DarkSword

The newly analyzed P7 DarkSword variant represents a sharp refinement in stealth, efficiency, and data exfiltration techniques. Security analysts note that the implant systematically eliminates legacy debug logging mechanisms over HTTP requests and system logs (syslog), heavily utilizing the device’s browser localStorage architecture to prevent redundant or accidental re-exploitation of already compromised handsets.

Unlike older iterations that typically copied and exfiltrated the raw keychain database for offline processing on external attacker-controlled infrastructure, P7 DarkSword processes the data locally. The variant systematically extracts sensitive keychain data into a structured JSON format directly on the victim’s smartphone prior to exfiltration, significantly minimizing the volume and visibility of network traffic. Once the implant is successfully injected into the SpringBoard process, it assumes full responsibility for handling persistent communication with the attacker’s infrastructure.

Technical telemetry reveals that the latest iteration is meticulously programmed to poll for new commands every 15 seconds. During these check-ins, the implant transmits a regular "heartbeat" message, provides an exhaustive inventory of all installed applications on the device, and relays deeply confidential information. This includes sensitive iCloud Keychain data alongside private records harvested from productivity and financial applications such as Apple Notes, Apple Photos, and various digital cryptocurrency wallets. The responses delivered during these periodic polling cycles supply the implant with direct execution tasks, allowing remote operators to dynamically control the compromised device.

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

Abandoned Infrastructure Hijacked to Deliver Mobile Spyware

In a parallel discovery that highlights the opportunistic nature of modern cybercrime ecosystems, researchers revealed that the P7 DarkSword exploit has also been distributed through compromised third-party domains. According to findings published by Report URI, unknown threat actors weaponized a domain previously utilized by a now-defunct Czech e-commerce analytics startup after the domain registration expired in September 2026.

The domain, registered under the address "ecomtrack[.]io," was seized by malicious operators to target online retail stores that still incorporated outdated tracking tags referencing the former analytics platform. Because numerous e-commerce websites failed to remove the abandoned tracking script, visitors to these stores were inadvertently hijacked. The injected JavaScript payload utilizes sophisticated evasive maneuvers to detect and evade web crawlers, headless browsers, and security bots by serving empty content to conceal its malicious intent.

After collecting initial reconnaissance data regarding the visitor’s device and browser environment, the malicious script redirects users toward scam websites or fraudulent online casinos. One primary redirection path leads victims to a bogus cryptocurrency trading platform known as "chainmate[.]top," which stealthily serves the DarkSword iOS exploit chain. The spyware payload delivered via this web-based vector is remarkably comprehensive, configured to capture SMS messages, contact lists, call histories, voicemails, photos, Apple Health data, location histories, device notifications, saved Wi-Fi passwords, and dedicated file stores belonging to more than 25 different cryptocurrency wallet applications.

Additional analysis of recovered code samples indicated that the build actively communicates with an infrastructure node at "mertio.cc" at 30-second intervals, executing high-privilege commands that include remote execution, payload downloading, photo harvesting, and active surveillance capabilities.

Broader Ecosystem Proliferation and Coruna Bundling

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

The public release of the DarkSword source code has triggered widespread experimentation across the underground threat landscape. In recent months, security researchers have observed numerous unsuccessful, largely automated attempts by lesser-skilled operators attempting to update the framework to support newer operating system versions, such as iOS 26.x, frequently with the assistance of large language models. While many of these attempts have resulted in broken or non-functioning binaries often circulated on GitHub, sophisticated groups continue to refine working iterations.

Furthermore, investigators have documented instances where DarkSword is bundled alongside Coruna, another prominent iOS exploit kit uncovered earlier in the year that targets older iPhone models running iOS versions 13.0 through 17.2.1. When deployed together—a combination researchers informally refer to as "DarkCoruna"—Coruna acts as a companion payload kit operating within the victim’s browser session after the initial DarkSword exploit stages have successfully landed. Its specialized modules focus heavily on harvesting cryptocurrency recovery phrases, balances, and keystore data directly from mobile applications.

Recent infrastructural scans conducted by Censys have identified open directories across multiple hosting providers containing exposed components related to both DarkSword and Coruna. Analysis of production server exploit registries and administrative control panels associated with these campaigns has further uncovered previously undocumented CVE identifiers leveraged within the exploitation chain. Investigators assess that several of these open-directory clusters and active command-and-control platforms are operated by Chinese-speaking threat actors running structured "exploitation-as-a-service" operations. These panels often expose agent and reseller models, revealing extensive rosters of compromised devices, cached victim recovery phrases, and centralized control planes as financially motivated groups continue to exploit the ongoing proliferation of leaked mobile attack tooling.

Leave a Reply

Your email address will not be published. Required fields are marked *