Cybersecurity experts have revealed new insights into P7 DarkSword, a variant of the DarkSword iOS exploit kit. This latest iteration stands out by minimizing its device footprint and introducing advanced capabilities such as crypto-wallet theft and bidirectional communication with the attacker’s network. This information was detailed in a report by iVerify published recently.
Enhanced Capabilities of P7 DarkSword
The ‘P7’ designation refers to the use of a specific variable prefix in the updated DarkSword code. Initially documented in early 2025, DarkSword’s ability to exploit iPhones running iOS versions 18.4 through 18.7 was reported by Google Threat Intelligence Group, iVerify, and Lookout. The exploit kit was first detected in the wild in November 2025.
The toolkit utilizes multiple iOS vulnerabilities to bypass browser sandbox restrictions, escalate privileges to the kernel level, and inject payloads into SpringBoard, the iOS process responsible for app management. It’s believed to be a commercial product that ended up on secondary markets, where financially motivated groups acquired it.
Targeted Attacks and Global Impact
The P7 DarkSword kit has been used in attacks against countries like Saudi Arabia, Turkey, Malaysia, and Ukraine. Among the operators, a Turkish surveillance vendor named PARS Defense has reportedly used a fake Snapchat site as a delivery mechanism, while a Russia-aligned group known as Star Blizzard has employed deceptive invitations.
In August 2026, a campaign by a Chinese-speaking threat actor targeted Apple iOS devices with the kit, including a fake Apple ID sign-in page as a decoy. Subsequent attempts to update the exploit to support iOS 26.x have been observed, indicating ongoing efforts to refine and deploy this tool.
Technical Evolution and Threat Analysis
P7 DarkSword further evolves by eliminating certain logging features and using localStorage to prevent repeated exploits. Unlike previous versions that offloaded keychain data for external processing, this version processes keychain information into JSON format directly on the device before exfiltration.
The implant interacts with the attacker’s infrastructure through the SpringBoard process, enabling a constant communication channel for data extraction and command execution. Capabilities include stealing iCloud Keychain data, accessing crypto wallet information, and executing system commands.
Broader Implications and Future Concerns
Recent analyses by Censys have identified open directories linked to both DarkSword and a companion kit named Coruna. Coruna operates alongside DarkSword, targeting browser sessions to capture crypto wallet data. These kits are used together against shared C2 infrastructure, highlighting a sophisticated ecosystem.
Discovery of specific CVE vulnerabilities within the DarkSword kit underscores the persistent threat to iOS devices. The platform has connections to Chinese-speaking threat actors, suggesting a coordinated effort to conduct financially motivated attacks. The ongoing evolution of these threats necessitates vigilance and prompt security updates from affected users.
