RC RANDOM CHAOS

iVerify discloses new DarkSword iOS variant

P7 DarkSword adds iOS wallet theft, keychain extraction, and remote command execution through SpringBoard-injected implants.

· 5 min read
iVerify discloses new DarkSword iOS variant

P7 DarkSword can poll its command server every 15 seconds, execute commands on the phone, extract iCloud Keychain data, pull Apple Notes and Photos data, and scan for cryptocurrency wallets.

That is the material change in the newly disclosed variant of the DarkSword iOS exploit kit. Earlier reporting on DarkSword centered on an exploit chain for iPhones running iOS 18.4 through 18.7, with the kit chaining multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject a payload into SpringBoard, the iOS process responsible for app launches and the home screen. P7 keeps that basic shape, but iVerify says it reduces the on-device footprint and adds two-way command-and-control.

The name comes from the attacker’s use of a p7_ variable prefix in changes made to the original DarkSword code. That is a small implementation detail, but it matters because this is not being described as a clean new family. It is an evolution of an exploit kit that has already moved through several hands.

DarkSword was detected in the wild in November 2025 and publicly documented in March by Google Threat Intelligence Group, iVerify, and Lookout. The kit has been used against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine by multiple actors, including PARS Defense through a fake Snapchat-themed site and Star Blizzard through fake invitation lures. In August 2026, Censys described a separate campaign by an unknown Chinese-speaking actor that targeted Apple iOS devices and served an Apple ID decoy sign-in page.

The newer P7 variant changes the post-exploitation problem. Prior DarkSword variants copied and exfiltrated the keychain database for processing on attacker infrastructure. P7 extracts keychain data into JSON on the phone before exfiltration. It also removes debug logging over HTTP requests and syslog, and uses browser localStorage to prevent re-exploitation.

Once the implant is injected into SpringBoard, it handles communication with the attacker’s infrastructure. The command set described by iVerify is broad enough to make the phone a managed endpoint for the operator. P7 can send heartbeat messages, enumerate installed applications, transmit iCloud Keychain information, upload photos from /var/mobile/Media/DCIM, pull Apple Notes databases, execute operating system commands, run arbitrary JavaScript inside the implant runtime, recursively scan the filesystem from /, upload matching files from selected paths, and alter its beacon interval with a sleep command.

For wallet theft, the important commands are wallet_scan, wallet_extract, and ios_app_data. The first scans for installed wallet apps. The second extracts wallet-related data for the imToken wallet app. The third finds app sandbox and app-group containers for requested bundle IDs and uploads selected app files. Censys separately described Coruna, another iOS exploit kit in the same ecosystem, as including wallet-harvesting modules that steal recovery phrases, balances, and keystore data from iOS apps. Censys says operators run DarkSword and Coruna together against their own C2 infrastructure.

That pairing has already appeared in the exposed infrastructure. Censys found five open-directory hosts carrying components related to DarkSword and Coruna. One served DS-Fusion v1.0, described as a combined DarkSword and Coruna package. Another operated as a C2 server and recorded two real Chinese iOS devices polling a beacon page every three seconds for several hours on September 6, 2026. A separate host exposed what Censys described as an analysis workspace showing development of exploit chains for iOS 26, including CVE-2026-31001, which are outside the DarkSword and Coruna coverage described in the source.

The production server’s exploit registry also exposed two DarkSword CVEs that had not previously been documented in public reporting: CVE-2025-24201, a WebKit out-of-bounds write fixed in iOS and iPadOS 18.3.2, and CVE-2025-31200, a Core Audio memory corruption issue fixed in iOS and iPadOS 18.4.1. In the registry, these sit behind a commercialized exploitation workflow rather than a one-off intrusion.

Censys assessed that the open-directory cluster and the exposed 156.239.230[.]120 platform were likely run by a Chinese-speaking threat actor focused on cryptocurrency wallet theft, while saying the specific operator is unknown. The exposed platform showed an agent and reseller model. Censys researcher Aidan Holland said a recovered production server copy contained 11 victim recovery phrases, 179 device loot directories, and a 75-account control-plane roster.

A second distribution route is messier and more opportunistic. Report URI found the same P7 DarkSword exploit distributed through ecomtrack[.]io, a domain once associated with a now-defunct Czech e-commerce analytics startup. Unknown actors re-registered the expired domain on September 15, 2026. Sites that still had the old analytics tag embedded began loading attacker-controlled JavaScript. Security researcher Scott Helme said the tag hijacked visitors, sold traffic to ad networks, and in one case delivered a full iOS exploit chain and spyware implant.

That JavaScript used cloaking to detect crawlers, headless browsers, and bots, serving them empty content. It collected device and browser information, sent it to an external server, and then redirected the visitor to a scam site or online casino. One route led to chainmate[.]top, a bogus cryptocurrency trading platform that served the DarkSword iOS exploit chain. The implant in that route was configured to contact mertio.cc every 30 seconds and handle commands including exec, download, photos, and spy. Helme said the recovered build appeared newer, reported to different infrastructure, and targeted far more crypto wallets, with files belonging to more than 25 wallet apps in scope.

For defenders, the useful part is the operational pattern. This is browser-delivered iOS exploitation followed by SpringBoard-resident collection, command polling, app container discovery, and wallet-focused file theft. The exposed infrastructure shows both packaged exploitation and service-style distribution. The expired analytics-domain route adds a supply-chain residue problem: abandoned third-party tags can become exploit delivery points long after the original vendor disappears.

The immediate controls are ordinary but specific. Remove dead third-party scripts from web properties instead of leaving expired vendor tags in place. Treat unexpected redirects from legacy analytics JavaScript as a security event, not an adtech nuisance. For iOS fleets, prioritize patch levels that include the fixes for the WebKit and Core Audio issues named in the exposed registry. For high-risk users with wallet exposure, installed wallet inventory and unusual device behavior matter because P7 has commands built around wallet app discovery, app container extraction, photo upload, notes upload, and filesystem scanning.

See also: NordVPN for tunneled traffic when operating outside controlled networks.


#ad Contains an affiliate link.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.