Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
P7 DarkSword iOS Exploit Kit Targets Crypto Wallets

P7 DarkSword iOS Exploit Kit Targets Crypto Wallets

Posted on October 9, 2026 By CWS

Cybersecurity experts have revealed new insights into P7 DarkSword, a variant of the DarkSword iOS exploit kit. This latest iteration stands out by minimizing its device footprint and introducing advanced capabilities such as crypto-wallet theft and bidirectional communication with the attacker’s network. This information was detailed in a report by iVerify published recently.

Enhanced Capabilities of P7 DarkSword

The ‘P7’ designation refers to the use of a specific variable prefix in the updated DarkSword code. Initially documented in early 2025, DarkSword’s ability to exploit iPhones running iOS versions 18.4 through 18.7 was reported by Google Threat Intelligence Group, iVerify, and Lookout. The exploit kit was first detected in the wild in November 2025.

The toolkit utilizes multiple iOS vulnerabilities to bypass browser sandbox restrictions, escalate privileges to the kernel level, and inject payloads into SpringBoard, the iOS process responsible for app management. It’s believed to be a commercial product that ended up on secondary markets, where financially motivated groups acquired it.

Targeted Attacks and Global Impact

The P7 DarkSword kit has been used in attacks against countries like Saudi Arabia, Turkey, Malaysia, and Ukraine. Among the operators, a Turkish surveillance vendor named PARS Defense has reportedly used a fake Snapchat site as a delivery mechanism, while a Russia-aligned group known as Star Blizzard has employed deceptive invitations.

In August 2026, a campaign by a Chinese-speaking threat actor targeted Apple iOS devices with the kit, including a fake Apple ID sign-in page as a decoy. Subsequent attempts to update the exploit to support iOS 26.x have been observed, indicating ongoing efforts to refine and deploy this tool.

Technical Evolution and Threat Analysis

P7 DarkSword further evolves by eliminating certain logging features and using localStorage to prevent repeated exploits. Unlike previous versions that offloaded keychain data for external processing, this version processes keychain information into JSON format directly on the device before exfiltration.

The implant interacts with the attacker’s infrastructure through the SpringBoard process, enabling a constant communication channel for data extraction and command execution. Capabilities include stealing iCloud Keychain data, accessing crypto wallet information, and executing system commands.

Broader Implications and Future Concerns

Recent analyses by Censys have identified open directories linked to both DarkSword and a companion kit named Coruna. Coruna operates alongside DarkSword, targeting browser sessions to capture crypto wallet data. These kits are used together against shared C2 infrastructure, highlighting a sophisticated ecosystem.

Discovery of specific CVE vulnerabilities within the DarkSword kit underscores the persistent threat to iOS devices. The platform has connections to Chinese-speaking threat actors, suggesting a coordinated effort to conduct financially motivated attacks. The ongoing evolution of these threats necessitates vigilance and prompt security updates from affected users.

The Hacker News Tags:Apple security, C2 communication, crypto theft, crypto wallet security, CVE vulnerabilities, Cybersecurity, DarkSword exploit, exploit kit, iOS exploit, iOS security, iPhone vulnerabilities, mobile security, P7 DarkSword, remote commands, Threat Actors

Post navigation

Previous Post: Anthropic’s OSS Scanner Enhances Open-Source Security
Next Post: GhostAction Breach Exposes GitHub Repositories to Secret Theft

Related Posts

Massive Credential Theft Targets FortiGate Firewalls Worldwide Massive Credential Theft Targets FortiGate Firewalls Worldwide The Hacker News
Google Fined €403M for GDPR Breaches in Location Data Google Fined €403M for GDPR Breaches in Location Data The Hacker News
TrueConf Server Vulnerabilities Exploited by Cybercriminals TrueConf Server Vulnerabilities Exploited by Cybercriminals The Hacker News
Android Malware Poses Threat to Mobile Banking Users Android Malware Poses Threat to Mobile Banking Users The Hacker News
Critical Flaw in Terrarium Sandbox Allows Code Execution Critical Flaw in Terrarium Sandbox Allows Code Execution The Hacker News
Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GhostAction Breach Exposes GitHub Repositories to Secret Theft
  • P7 DarkSword iOS Exploit Kit Targets Crypto Wallets
  • Anthropic’s OSS Scanner Enhances Open-Source Security
  • Exploit Exposes Root Access Flaw in AnyDesk Linux
  • Warden Stealer Malware Expands via ClickFix and Malvertising

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GhostAction Breach Exposes GitHub Repositories to Secret Theft
  • P7 DarkSword iOS Exploit Kit Targets Crypto Wallets
  • Anthropic’s OSS Scanner Enhances Open-Source Security
  • Exploit Exposes Root Access Flaw in AnyDesk Linux
  • Warden Stealer Malware Expands via ClickFix and Malvertising

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark