P7 DarkSword iOS variant steals keychain, wallets and Notes
iVerify found P7 DarkSword, a new variant of the DarkSword iPhone exploit kit, on a customer device in August 2026. It runs inside SpringBoard, extracts keychain data on the phone, steals wallet data, Photos and Notes, and polls for remote commands every 15 seconds. DarkSword targets iOS 18.4 to 18.7. All six chained CVEs are fixed and in CISA KEV.
Published 9 Oct 2026
On this page
What happened
On 8 October 2026 the mobile security company iVerify published a report on a new DarkSword variant. It calls the variant P7 DarkSword. The name comes from a p7_ prefix the operators used in the code they added to the original DarkSword source.
iVerify found P7 during an incident response in August 2026. One of its customers' phones raised a DarkSword alert that looked slightly different from usual. With the customer's consent, iVerify collected forensic artifacts. Those confirmed an unknown variant. In comments to 9to5Mac, iVerify said the phone belonged to an employee of a financial institution.
In parallel, iVerify hunted for DarkSword content on the internet using the Validin platform. It found a suspicious domain that matched the infection timeline. That domain hosted another copy of the same spyware, which iVerify analysed.
iVerify sums up the change in one sentence. Compared with the variants it usually sees, P7 "reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure."
P7 is not a new iOS vulnerability. It is a new version of the spyware that runs after the existing DarkSword exploit chain has compromised a phone. The chain itself still relies on bugs that Apple fixed between July 2025 and February 2026.
What DarkSword is
DarkSword is an exploit chain for iPhones. Google Threat Intelligence Group (GTIG) disclosed it on 18 March 2026, in coordination with iVerify and Lookout. GTIG named it from toolmarks in recovered payloads.
According to GTIG, DarkSword supports iOS 18.4 through 18.7. It chains six vulnerabilities to take a phone from a web page to full kernel privileges. Every stage, and the final payloads, are written in JavaScript. GTIG notes that this design avoids the need for extra bugs to run unsigned native code.
GTIG observed DarkSword in the wild since at least November 2025. It saw several commercial surveillance vendors and suspected state-sponsored actors use it in separate campaigns. Targets were in Saudi Arabia, Turkey, Malaysia and Ukraine.
GTIG documented three malware families delivered after a DarkSword compromise:
- GHOSTKNIFE, a backdoor used by the cluster GTIG tracks as UNC6748.
- GHOSTSABER, a backdoor used by customers of the Turkish vendor PARS Defense.
- GHOSTBLADE, a data miner used by UNC6353, a suspected Russian espionage group.
iVerify reported the Ukrainian watering hole attacks on the same day. It traced the first stage to two compromised Ukrainian websites, one of them on a government domain. In that campaign the exploit fired only for iPhones on iOS 18.4 to 18.6.2 with a Ukrainian IP address. iVerify estimated that up to 270 million devices were still on the affected versions at the time.
iVerify later wrote that DarkSword's source code was leaked by a third party soon after the March disclosure. Since then it has tracked multiple clusters of variants. In September 2026 it said it saw "multiple unsuccessful, likely LLM-assisted attempts" to port the kit to iOS 26. Most variants, it said, focus on stability, stealth, and the quality of stolen data.
Other operators followed. SecurityWeek reported on 30 March 2026 that Proofpoint linked an email campaign with Atlantic Council lures to Star Blizzard, an FSB-linked group also tracked as COLDRIVER and TA446. Proofpoint found a known Star Blizzard domain serving DarkSword components. It did not observe the sandbox escapes or the final delivery.
On 7 October 2026 Censys described a Chinese-speaking "exploitation-as-a-service" operation running DarkSword alongside Coruna, an older iOS kit. Censys said a copy of that operator's production server held 11 victim wallet recovery phrases and 179 device loot directories. Censys also found a separate China-based operator using the same wallet-theft modules in the wild.
What's new in P7
iVerify groups the changes into three areas: stealth, stability, and functionality. Each is described below as iVerify reports it.
Stealth
Earlier DarkSword builds sent debug logs over web requests and wrote to the system log. P7 removes both. It also reduces the number of process injections it performs.
iVerify told 9to5Mac that P7 is much better at hiding itself and cleaning up. As a result, older DarkSword indicators of compromise no longer match it.
Stability
P7 uses the browser's local storage to mark phones it has already attacked. This stops it from exploiting the same device twice. Repeated exploitation can crash processes and leave traces.
On-device keychain extraction
Earlier DarkSword versions copied the whole keychain database off the phone. The attackers then processed it on their own servers. P7 instead extracts keychain entries on the phone itself, writes them to a JSON file, and sends that file out.
iVerify uses the word "keychain" without further detail. Some news coverage calls this "iCloud Keychain" data. The primary report does not say whether the stolen entries are limited to local items or include items synced through iCloud.
Crypto wallet theft
P7 can scan the phone for installed cryptocurrency wallet apps. It has a dedicated routine to extract data from the imToken wallet. Keychain and wallet data are sent to the attackers together.
Photos and Apple Notes
P7 can upload photo files from the camera roll. It can also query the Photos database for recent pictures and upload them. It finds Apple Notes databases, copies them to a temporary folder, and uploads them.
Censys notes that wallet-theft tooling in the same ecosystem searches photos and Notes for crypto recovery phrases. iVerify does not say why P7 collects Photos and Notes.
Two-way remote control
This is the largest change. Earlier variants mostly grabbed data and left. P7 keeps a command loop open with the attackers' server.
By default the implant checks in every 15 seconds and asks for new tasks. The operators can change this interval remotely, or tell the implant to stop.
iVerify lists the tasks the implant accepts. In plain terms, the operators can:
- run shell-style commands on the phone;
- list folders and download any file the implant can read;
- inventory installed apps and their data containers;
- upload selected files from chosen apps;
- scan the whole file system and upload a report;
- collect basic device information;
- run new JavaScript inside the implant.
The last point matters. It means the operators can add behaviour after infection without sending a new exploit.
The implant also sends a registration message, a periodic heartbeat, and a list of installed apps.
How the implant runs
This section stays at a high level. It does not describe exploit internals.
After the exploit chain reaches kernel privileges, the P7 implant is injected into SpringBoard. SpringBoard is the iOS process that draws the home screen and launches apps. iVerify says SpringBoard handles all communication with the attackers.
Running inside a core system process has two effects. The implant inherits broad access to user data. And its network traffic comes from a process that is always running.
Like the original DarkSword, P7 works from memory and from temporary files. iVerify found several artifacts in the system's temporary directory during its investigation. These include keychain dump files and debug journals. The names are listed in the Indicators section below.
iVerify's report does not describe a persistence mechanism for P7. The original DarkSword did not try to survive a reboot. iVerify has described it as built for a "smash and grab". Whether P7 survives a restart is not stated.
iVerify says the traffic uses HTTPS without strict certificate checks. All requests use a fixed iPhone Safari user agent that claims iOS 18.5.
Infection chain and exploited vulnerabilities
DarkSword is delivered through the browser. GTIG describes three base delivery patterns: a fake Snapchat-themed site in Saudi Arabia, PARS Defense infrastructure in Turkey and Malaysia, and compromised Ukrainian websites. Star Blizzard used links in emails. Censys found a Chinese-language landing page with a button leading to the exploit page.
For P7, iVerify told 9to5Mac that the operator spreads it through malicious ads as part of watering hole attacks. Victims therefore do not appear to be picked one by one.
The chain then moves through four stages, according to GTIG:
- remote code execution in Safari's JavaScript engine;
- a bypass of pointer authentication, a hardware defence against code reuse;
- two sandbox escapes, first into the browser's GPU process, then into a media system service;
- a kernel privilege escalation.
GTIG lists these six CVEs. The fixed iOS versions come from GTIG and Apple. The KEV dates come from the CISA catalog checked on 9 October 2026.
- CVE-2025-31277. JavaScriptCore memory corruption, used on iOS before 18.6. Fixed in iOS 18.6. Not a zero-day when used, per GTIG. Added to CISA KEV on 20 March 2026.
- CVE-2025-43529. JavaScriptCore memory corruption, used on iOS 18.6 and 18.7. Exploited as a zero-day. Fixed in iOS 18.7.3 and 26.2. Added to KEV on 15 December 2025.
- CVE-2026-20700. Pointer authentication bypass in dyld, the dynamic linker. Exploited as a zero-day. Fixed in iOS 26.3. Added to KEV on 12 February 2026.
- CVE-2025-14174. Memory corruption in ANGLE, a graphics library, giving the WebContent sandbox escape. Exploited as a zero-day. Fixed in iOS 18.7.3 and 26.2. Added to KEV on 12 December 2025, listed under Google Chromium.
- CVE-2025-43510. Kernel memory management flaw, giving the GPU process escape. Fixed in iOS 18.7.2 and 26.1. Added to KEV on 20 March 2026.
- CVE-2025-43520. Kernel memory corruption, giving kernel privileges. Fixed in iOS 18.7.2 and 26.1. Added to KEV on 20 March 2026.
Apple's iOS 26.3 notes say CVE-2026-20700 "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 26." The same notes say CVE-2025-14174 and CVE-2025-43529 were issued in response to that report.
The P7 copies iVerify recovered include exploit modules named for iOS 18.4, 18.5, 18.6 and 18.7. iVerify told 9to5Mac that P7 extends support to iOS 18.7, up from 18.6 in the earlier variant it tracked. GTIG had already seen 18.7 support in other DarkSword deployments.
Censys reported two more CVEs in one operator's exploit registry. These are CVE-2025-24201, a WebKit flaw fixed in iOS 18.3.2, and CVE-2025-31200, a CoreAudio flaw fixed in iOS 18.4.1. Both are in KEV, added on 13 March 2025 and 17 April 2025. Censys says the CoreAudio entry is an unverified claim in that registry. Neither CVE is part of the P7 chain iVerify describes.
Censys also found unfinished work on an iOS 26 chain built around CVE-2026-31001. That CVE ID is only reserved on CVE.org and has no public record. Censys says the chain is not deployed and should not be reported as a live capability.
Who is targeted
DarkSword only works on iPhones running iOS 18.4 through 18.7 that have not received the fixes. Phones on iOS 26.3 or later, or on iOS 18.7.6 or later, are outside the documented chain. iVerify said in March that updating to iOS 18.7.6 or 26.3.1 mitigates every vulnerability used in the attack chains.
The confirmed P7 victim was an employee of a financial institution, according to 9to5Mac. iVerify does not name the institution or the country. It also does not say which iOS version the phone was running.
Earlier DarkSword campaigns hit users in Saudi Arabia, Turkey, Malaysia and Ukraine. Star Blizzard's lures went to government, higher education, financial and legal organisations and to think tanks, per Proofpoint. The Chinese-speaking cluster Censys described focused on crypto wallet theft, and the two live devices it saw were in mainland China and Hong Kong.
The wide spread of DarkSword makes targeting less predictable. Watering holes and malicious ads can reach anyone who visits the wrong page on an old iPhone.
What is confirmed
These points are stated in primary research or official sources:
- iVerify found P7 DarkSword on a customer phone in August 2026 and published its analysis on 8 October 2026.
- P7 runs inside SpringBoard and handles all attacker communication from there.
- P7 extracts keychain data to JSON on the phone before sending it out.
- P7 can scan for wallet apps and extract imToken wallet data.
- P7 can steal Photos and Apple Notes databases.
- P7 accepts remote commands, including file download, file system scans, app data theft, shell-style commands and new JavaScript.
- P7 checks in every 15 seconds by default, and the interval is configurable.
- P7 drops debug logging over HTTP and syslog, injects into fewer processes, and uses browser storage to avoid re-exploitation.
- DarkSword has been used in the wild since at least November 2025, per GTIG.
- All six DarkSword CVEs are patched by Apple and listed in CISA KEV.
- Apple widened the availability of iOS 18.7.7 on 1 April 2026 to protect more devices from what it calls "web attacks called DarkSword."
What is not confirmed
Several points remain open or are disputed between sources:
- Who runs P7. iVerify does not attribute the variant to any group.
- Scale. iVerify documents one confirmed infection and one hosting domain. It gives no victim count.
- The victim's iOS version and the exact entry page used.
- Whether "keychain" means only local items or also iCloud Keychain items. Some coverage says iCloud Keychain; iVerify does not.
- Whether P7 survives a reboot. The report does not say.
- Whether Lockdown Mode stops P7 specifically. The P7 report does not test it. The guidance below comes from the March reports on DarkSword.
- Whether P7 is linked to the Chinese-speaking cluster Censys described. Neither company draws that link.
- Any working DarkSword chain for iOS 26 or later. iVerify saw failed porting attempts. Censys saw unfinished work around a CVE that has no public record. Neither reports a deployed chain.
- Censys's account of the production server comes from a package of unknown origin, as Censys itself notes.
Indicators
The indicators below are copied from iVerify's P7 report. They are defanged and not clickable. Do not visit them.
Exploit delivery domains:
- cdn[.]gotoiphone[.]com
- mzpo30[.]cam
Command and control:
- agdx53[.]cc
- js[.]gotoiphone[.]com
On-device file names, all in the system temporary directory, per iVerify:
keychain_c2_dump.json, with matching.tmpand.donefilesp7_debug.logc2_wallet_debug.log_hq_notestore, with-waland-shmcopiesnotes.sqlitecopies, with-waland-shmfiles
iVerify also lists a disk scan report named ios_disk_scan.txt, in the mobile user's home or caches folder. It is uploaded in chunks and then deleted.
Browser local storage keys set by the two delivery sites are a further sign. iVerify lists keys starting with __ds_ and _x_, plus one named lab_device_uuid.
iVerify publishes SHA-256 hashes for every exploit and implant module it recovered. It also publishes a long list of other DarkSword and Coruna domains and C2 addresses. Use the iVerify report for those full lists rather than copying them by hand.
Censys published separate indicators for the Chinese-speaking cluster. They include the wild-build C2 domain 66ds[.]lol and five open-directory hosts. Those indicators relate to DarkSword and Coruna operators generally, not to P7.
What to do
Update every iPhone and iPad. As of 9 October 2026, Apple's current releases are iOS 27.0.1, iOS 26.7.1 and, for older devices such as the iPhone XS and XR, iOS 18.7.10. Any of these is far beyond the fixes DarkSword needs to fail.
If a device must stay on iOS 18, make sure it runs at least iOS 18.7.6. Apple made iOS 18.7.7 available to more devices on 1 April 2026 for this reason. Turn on Automatic Updates.
If you cannot update, GTIG recommends turning on Lockdown Mode. iVerify said in March that the DarkSword exploits would not work without extra bypasses on devices with Lockdown Mode enabled. It said the same of iPhone 17 models with Memory Integrity Enforcement enabled. Lockdown Mode limits some web features, so test it first.
For organisations:
- Find managed iPhones still on iOS 18.4 to 18.7.5 and force an update.
- Block the published domains at DNS and web proxies.
- Hunt in DNS and proxy logs for past contact with those domains.
- Treat employees who hold crypto keys, payment approval or privileged access as higher risk.
If you suspect a compromise:
- Update the phone at once, then restart it.
- Assume that passwords, tokens and keys stored in the keychain are exposed. Change those passwords from a clean device and revoke app sessions.
- Move crypto funds to a new wallet created on a clean device, with a new recovery phrase. Do not reuse any phrase kept in Photos, Notes or a wallet app on the old phone.
- Treat photos and notes as read by the attacker.
- Check your Apple Account for unknown devices and sessions.
iVerify says its apps detect DarkSword infections and provides the indicators above for forensic checks. Organisations without mobile threat detection can still check DNS logs and look for the listed file names in device forensic images.
Sources: iVerify's P7 DarkSword report and its earlier DarkSword posts, Google GTIG's DarkSword report, Lookout, Censys, Apple security notes for iOS 26.3 and 18.7.7, the CISA KEV catalog, NVD, 9to5Mac, SecurityWeek, Help Net Security, and The Hacker News.
Sources
- iVerify, P7 DarkSword variant (8 October 2026)
- iVerify, Proliferation of Coruna and DarkSword (15 September 2026)
- iVerify, Inside DarkSword (18 March 2026)
- iVerify, lessons from DarkSword for enterprises
- Google GTIG, The Proliferation of DarkSword (18 March 2026)
- Lookout, DarkSword exploit kit
- Censys, DarkSword/Coruna open directory report (7 October 2026)
- Apple, security content of iOS 26.3
- Apple, security content of iOS 18.7.7
- Apple security releases
- CISA Known Exploited Vulnerabilities catalog
- NVD, CVE-2026-20700
- 9to5Mac, new DarkSword variant (8 October 2026)
- SecurityWeek, Star Blizzard adopts DarkSword (30 March 2026)
- Help Net Security, DarkSword (19 March 2026)
- The Hacker News, P7 DarkSword (9 October 2026)