Researchers at iVerify have detailed P7 DarkSword, a new variant of the iOS exploit kit first documented in March by Google Threat Intelligence Group, iVerify, and Lookout. Compared with earlier versions, P7 reduces its on-device footprint, adds keychain and cryptocurrency wallet theft, and uses two-way C2 communication with attacker infrastructure. The original kit chains multiple iOS vulnerabilities to escape the browser sandbox, gain kernel privileges, and inject a payload into SpringBoard.
P7 removes debug logging over HTTP and syslog, and uses browser localStorage to avoid re-exploitation. Instead of copying the keychain database for off-device processing, it extracts keychain data into JSON on the phone before sending it out. The implant in SpringBoard polls for commands every 15 seconds, supporting actions such as executing OS commands, uploading files, scanning disks, enumerating installed apps, extracting Apple Notes and photos, and pulling data from the imToken wallet app.
The kit continues to be used by multiple threat actors, including Turkish surveillance vendor PARS Defense and Russia-aligned Star Blizzard; a Chinese-speaking actor was also observed targeting Apple devices with it. iVerify says it recently saw multiple unsuccessful, likely LLM-assisted attempts to update the framework for iOS 26.x. Separately, Censys found open directories on five hosts linking DarkSword to the companion Coruna payload kit, which steals crypto recovery phrases, balances, and keystore data. One host exposed a workspace where an operator was developing iOS 26 exploits, such as CVE-2026-31001, and another served as a C2 server that recorded real Chinese iOS devices polling a beacon page.