P7 DarkSword iOS exploit steals crypto wallets and adds remote control

Researchers say a new P7 DarkSword variant narrows its footprint, extracts keychain and wallet data on-device, and adds two-way command-and-control. Here is who it hit, how it spreads, and practical steps.

Smartphone on a desk with paper crypto wallets, USB drive, network cable, and an analytics tag sticker

Researchers disclosed a new variant of the DarkSword iOS exploit kit, labeled P7 DarkSword, that adds on-device extraction of keychain and cryptocurrency wallet data and two-way command control, according to The Hacker News and iVerify. The new build also reduces debug logging and the visible on-device footprint, researchers said.

What the P7 DarkSword iOS exploit does

According to iVerify as reported by The Hacker News, P7 chains multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject a payload into SpringBoard, the iOS process that manages app launches and the home screen. The implant runs inside SpringBoard and polls an operator server, sending a heartbeat and device details while awaiting commands.

iVerify described the implant as able to extract iCloud Keychain entries and data from apps including Apple Notes, Photos, and more than 25 wallet apps. The kit can perform a range of remote actions when commanded, including listing directories, downloading files, uploading photos, scanning app containers, extracting wallet data for specific wallets, and even executing arbitrary JavaScript inside the implant runtime.

The Hacker News cited iVerify saying P7 "reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure." The report also noted a common bundled pairing of DarkSword with a companion payload called Coruna.

How it has been delivered and who was targeted

DarkSword was first documented earlier this March by Google Threat Intelligence Group, iVerify, and Lookout, with initial detections in the wild in November 2025. The exploit kit has been used in attacks against devices in Saudi Arabia, Turkey, Malaysia, and Ukraine. The Hacker News reported deployments that included fake Snapchat-themed pages and invitation lures tied to different operators.

Researchers also described one notable delivery route involving a re-registered analytics domain. Security researcher Scott Helme told The Hacker News that the domain for a now-defunct Czech e-commerce analytics startup was re-registered and used to serve malicious JavaScript to stores that still include the old tracking tag. That tag can hijack visitors, chain them through ad networks, and in one instance deliver a full iOS exploit chain and spyware implant.

Censys added that it found open directories exposing components for DarkSword and Coruna, and linked hosts that appear to serve a combined package and operator infrastructure. Censys called Coruna the companion payload kit and said its wallet-harvesting modules target recovery phrases, balances, and keystore data.

Technical details researchers highlighted

Analysis recovered a production server exploit registry showing two CVE identifiers associated with the DarkSword kit, which were not previously documented in the public write-ups, The Hacker News reported. The recovered JavaScript used cloaking techniques to hide from crawlers and bots and to fingerprint devices before redirecting victims to scam pages or payload hosts.

iVerify and Censys observed multiple attempts to adapt the framework toward newer iOS releases, including some unsuccessful builds researchers described as likely assisted by large language models. iVerify also noted rare bundled deployments where DarkSword and Coruna are combined into a single package sometimes called DS-Fusion.

What small organizations and site owners should do now

If your site uses third-party tags or you run an online store, the delivery method described in these reports shows why those tags deserve attention. Actions to consider, guided by the reported findings:

  • Review and remove any unused third-party tracking tags or scripts, and lock who can change site code or tags. Third-party tags can become a vector if they are re-registered or compromised.
  • Scan your public-facing site for unexpected JavaScript, and treat any newly added analytics or widgets as potentially hostile until verified. Consider a Content Security Policy and subresource integrity where practical.
  • For staff and stakeholders who use iPhones: apply security updates from the vendor, enable multi-factor authentication, and limit which apps and links are opened on work devices. The implant targets data already on the device, including keychain and wallet data, according to researchers.
  • Audit who can register or renew domains and monitor any expired vendor domains your site still references.

If you want to check whether external tags on your site could be a risk, start with a free external scan on our security page: /security.html.

Why this matters to you

The P7 variant shows the threat actors are focusing on stealth, high-value data, and remote control. For businesses that accept crypto payments, rely on third-party analytics, or allow staff to access sensitive accounts from mobile devices, a chained browser exploit that extracts keychain entries and wallet data raises a higher-stakes risk than a simple phishing page.

The reporting from The Hacker News, iVerify, and Censys documents both the technical capabilities and the operational routes used to distribute the kit. That combination makes attention to third-party code hygiene, patching, and device security a practical priority for small businesses and public teams.

Sources

This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.

Found this useful? Pass it on to someone who would want to know.

NetScaler RCE vulnerability: patch Citrix NetScaler now

Citrix has released fixes for CVE-2026-107406, a memory overflow that can allow remote code execution or denial of service when NetScaler is used for SAML. Public scans show many NetScaler devices exposed, so check and update immediately.

All Online Security posts →

Cookie Notice

We use cookies to enhance your browsing experience and analyze site traffic. By clicking "Accept All", you consent to our use of cookies.