Cybersecurity researchers have uncovered a previously unseen and highly evolved variant of the DarkSword iOS exploit kit, designated by analysts as P7 DarkSword. The discovery highlights the continuous maturation and aggressive distribution of sophisticated mobile exploitation frameworks across global cybercrime and commercial surveillance ecosystems. According to a detailed technical report published by mobile security firm iVerify, this newly identified iteration departs significantly from traditional deployments observed in earlier campaigns. Compared with the variants usually encountered by threat intelligence analysts, the P7 variant dramatically reduces its on-device operational footprint while introducing advanced native capabilities, including on-device keychain and cryptocurrency wallet theft, alongside robust two-way command and control communication with attacker-controlled infrastructure. Read Also: French Tax Authority Data Breach Exposes Records of Hundreds of Thousands After Weak Security Exploited OpenAI Ousts Safety Researchers Amid Growing Scrutiny Over Autonomous AI Risks and Unauthorized System Probes The nomenclature "P7" serves as a direct technical nod by security researchers to the threat actor’s distinct use of the "p7_" variable prefix within modifications introduced to the foundational source code of the original DarkSword toolkit. The DarkSword exploit framework first came to public prominence in March of this year, when a coordinated disclosure by the Google Threat Intelligence Group (GTIG), iVerify, and Lookout exposed its formidable capabilities. The original toolkit was engineered to target iPhones operating on iOS versions ranging from iOS 18.4 to 18.7, having been actively detected in the wild as early as November 2025. Engineered as a multi-stage attack chain, the toolkit systematically leverages a sequence of iOS vulnerabilities to break out of the native browser sandbox, escalate privileges to the kernel level, and finally inject its primary operational payload into SpringBoard, the core system process responsible for managing application launches and the user interface home screen. Industry assessments indicate that the exploit chain originated as a commercial surveillance product that somehow leaked into the secondary market. From there, it was acquired by financially motivated threat actors and various state-aligned espionage groups beginning in late 2025. Since its initial public exposure, the DarkSword exploit kit has been linked to targeted operations across multiple geographical regions, including Saudi Arabia, Turkey, Malaysia, and Ukraine. Notable operators identified by researchers include a Turkish commercial surveillance vendor known as PARS Defense—which deployed the toolkit through fake, Snapchat-themed phishing websites—and a Russia-aligned threat actor tracked as Star Blizzard, also known as COLDRIVER, which utilized deceptive invitation lures. Additional campaigns emerged later in the year. In August, attack surface management platform Censys detailed a malicious operation conducted by an unknown Chinese-speaking threat actor. This campaign actively targeted Apple iOS devices using the exploit kit while simultaneously serving fraudulent Apple ID decoy sign-in pages to harvest user credentials. As researchers continued to monitor the underground proliferation of the toolkit following its disclosure, iVerify observed multiple unsuccessful, likely large language model-assisted attempts by various low-tier threat actors to update the framework to support newer iOS versions, specifically iOS 26.x. These unauthorized modification attempts were primarily driven by stability issues, stealth optimization, and a desire to maximize the quality of harvested data. Furthermore, iVerify noted that in rare instances, DarkSword had been observed bundled alongside another prominent mobile exploit kit known as Coruna, creating a hybrid threat ecosystem referred to by researchers as DarkCoruna. Analysis of these bundled variants revealed that attackers had directly obtained and modified the source code of the Coruna exploit kit without relying on simple binary patching, performing extensive code rewrites compiled into entirely new binaries. While many of these sightings involved poorly constructed modifications deployed by unsophisticated actors leveraging AI tools, security firms emphasize that the capability of actors to reverse-engineer and adapt complex mobile exploits remains an escalating concern. The P7 DarkSword variant represents a clear evolutionary leap in stealth and efficiency. It systematically eliminates traditional debug logging over HTTP requests and system logs, utilizing browser local storage mechanisms to prevent redundant re-exploitation attempts. Unlike older variants that simply copied and exfiltrated raw keychain databases to be processed offline on attacker infrastructure, the new P7 version extracts keychain data directly into structured JSON formats on the victim’s device prior to exfiltration. The underlying implant is injected directly into the SpringBoard process, which subsequently manages all external communication channels with the attacker’s infrastructure. This latest iteration is fully equipped to poll for operator commands every 15 seconds, transmit regular heartbeat signals, compile and send lists of installed applications, and siphon sensitive data from iCloud Keychains, Apple Notes, Photos, and numerous cryptocurrency wallet applications. The operational flexibility of P7 DarkSword is further amplified by its reliance on compromised web infrastructure and abandoned digital assets. Recent investigations by security researcher Scott Helme at Report URI revealed that the same P7 exploit chain has been distributed via a domain formerly associated with a defunct Czech e-commerce analytics startup. Following its expiration, unknown threat actors re-registered the domain to weaponize online retail websites that still embedded tracking tags referencing the legacy analytics product. When visitors browse e-commerce platforms still featuring the orphaned tag, the injected malicious JavaScript hijacks the session, feeds cloaked, empty content to web crawlers and automated bots to evade detection, and collects detailed device and browser telemetry. Visitors are then redirected toward scam websites or fraudulent online cryptocurrency trading platforms, such as a domain designated as chainmate.top, which covertly delivers the DarkSword iOS exploit chain. The malware delivered through this supply-chain vector is exceptionally thorough, capturing SMS messages, contact lists, call histories, voicemails, photos, Apple Health data, location histories, notifications, saved Wi-Fi passwords, and dedicated file directories belonging to more than 25 distinct cryptocurrency wallet applications. Recovered code samples indicate active communication with secondary command and control infrastructure every 30 seconds to handle advanced operational commands including execution, file downloads, photo gathering, and general espionage tasks. Concurrent findings from Censys revealed open directories hosted on multiple servers carrying operational components linked to both DarkSword and Coruna. According to Censys, Coruna functions as a companion payload kit operating within the same threat ecosystem, executing secondary stages inside victim browser sessions after DarkSword successfully establishes an initial foothold. Its specialized wallet-harvesting modules are designed to extract recovery phrases, cryptographic balances, and keystore data from mobile applications. An exhaustive forensic analysis of production servers associated with these campaigns has uncovered previously undocumented vulnerability identifiers leveraged within the DarkSword exploit registry, underscoring the depth of zero-day or advanced exploit research embedded within the kit. Industry analysts suspect that a significant portion of these open-directory clusters and exploitation infrastructure platforms are operated by Chinese-speaking threat actors running an exploitation-as-a-service model, complete with administrative panels, reseller networks, and extensive logs containing victim recovery phrases and harvested device directories. Additional campaigns linked to separate China-based operators utilizing Tencent and Shenyang hosting infrastructure continue to emerge, highlighting the widespread commercialization and availability of advanced iOS exploitation tools within the underground cybercrime economy. Post navigation New P7 DarkSword iOS Exploit Variant Emerges with Reduced Footprint and Advanced Crypto-Theft Capabilities