Threats · Mobile Exploit Kits
P7 DarkSword: iOS Exploit Kit Variant Adds Crypto-Wallet Theft and Two-Way C2
A new variant of the DarkSword iOS exploit kit shrinks its on-device footprint while adding on-device keychain and crypto-wallet theft, per iVerify’s Oct 8 report — and the toolkit appears to be circulating on a second-hand commercial market.
Photo: Ka Kit Pang, Public domain, via Wikimedia Commons
iVerify published a report on Oct 8 documenting “P7,” a new variant of the DarkSword iOS exploit kit that has been active in the wild since August 2026. “Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure,” iVerify said in the report, via The Hacker News.
The name “P7” comes from the threat actor’s use of the “p7_” variable prefix in changes to the original DarkSword code. DarkSword was first publicly documented in March 2026 by Google Threat Intelligence Group (GTIG), iVerify, and Lookout; it targets iPhones running iOS 18.4–18.7 and was detected in the wild in November 2025.
How the toolkit works
The toolkit chains multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject the payload into SpringBoard, Apple’s app-launch interface. The exploit chain is assessed to be a commercial product that reached a second-hand market, acquired by financially motivated operators since late 2025 — meaning the capability is no longer confined to its original developers.
P7’s additions — a smaller footprint to evade detection, keychain and crypto-wallet theft for direct monetization, and two-way command-and-control for interactive operation — reflect a shift toward financially motivated deployment rather than pure espionage.
Photo: ΙΡΗΟΝΕ 15, CC BY-SA 4.0, via Wikimedia Commons
Who is using it
The kit has been used against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine, according to the reporting. Operators include the Turkish commercial surveillance vendor PARS Defense, which used a fake Snapchat-themed website, and Russia-aligned Star Blizzard (also known as COLDRIVER), which used fake invitation lures. Censys separately detailed an August 2026 campaign by an unknown Chinese-speaking threat actor using the kit alongside an Apple ID decoy sign-in page.
What we know
- iVerify documented the P7 variant in a report published Oct 8, 2026; it has been active in the wild since August 2026.
- P7 reduces its on-device footprint and adds on-device keychain and crypto-wallet theft plus two-way C2 communication, per iVerify.
- The toolkit chains iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject into SpringBoard.
- The exploit chain is assessed to be a commercial product circulating on a second-hand market, acquired by financially motivated operators since late 2025.
- Targets include users in Saudi Arabia, Turkey, Malaysia, and Ukraine; operators include PARS Defense and Star Blizzard (COLDRIVER).
What remains unknown
- The precise delivery vector for the P7 variant is not detailed in the sources read.
- Apple’s mitigation and patch status for the chained flaws — no CVE IDs are assigned to the P7 variant in the sources read.
What you can do
- Keep iOS updated to the latest version available — exploit chains depend on unpatched vulnerabilities.
- Treat unexpected invitation links and lookalike sign-in pages (including Apple ID decoys) as hostile until verified.
- Enable Lockdown Mode if you are in a higher-risk profile; check Apple’s current iOS security guidance for the latest protections.
No corrections have been published for this article.