Cybersecurity experts have unveiled details about a new variant of the DarkSword iOS exploit kit known as P7 DarkSword.
The P7 variant of DarkSword differs from previous versions by reducing its on-device footprint, incorporating on-device keychain and crypto-wallet theft, and enabling two-way communication with the attacker’s infrastructure. iVerify reported these findings in a recent publication.
This variant, named P7, references the threat actor’s use of the “p7_” variable prefix in modifications made to the original DarkSword code.
DarkSword was initially documented by Google Threat Intelligence Group (GTIG), iVerify, and Lookout earlier this year, showcasing its ability to target iPhones running iOS versions between 18.4 and 18.7. The exploit kit was first detected in the wild in November 2025.
The DarkSword toolkit is designed to exploit multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject the main payload into SpringBoard, the iOS process responsible for app launches and the home screen. It is believed to be a commercial product that found its way into the hands of financially motivated operators and other threat actors through a second-hand market since late 2025.
Various threat actors, including a Turkish commercial surveillance vendor named PARS Defense and a Russia-aligned group known as Star Blizzard (COLDRIVER), have utilized the exploit kit in attacks targeting countries like Saudi Arabia, Turkey, Malaysia, and Ukraine. These attacks were carried out through fake websites and invitation lures.
Recently, iVerify observed unsuccessful attempts to update the framework supporting iOS 26.x following the leak of the exploit kit. These new variants focus on stability, stealth, and the quality of stolen data.
The P7 DarkSword variant represents a shift in strategy by eliminating debug logging over HTTP requests and syslog and using browser localStorage to prevent re-exploitation. Unlike previous versions, P7 extracts keychain data into JSON on the device before exfiltration.
The implant is injected into the SpringBoard process, enabling communication with the attacker’s infrastructure. The latest version of P7 DarkSword polls for commands every 15 seconds, sends a “heartbeat” message, transmits installed applications list, and gathers iCloud Keychain information and data from various apps.
The response to the periodic tasking poll includes commands such as executing operating system commands, listing directory contents, downloading files, uploading photos, enumerating app containers, executing arbitrary JavaScript, and scanning and uploading files, among others.
Furthermore, the P7 DarkSword exploit has been distributed through a domain linked to a defunct Czech e-commerce analytics startup. Unknown threat actors re-registered the domain to infect sites still using tracking tags referencing the analytics product with malicious JavaScript delivering the malware.
The new JavaScript includes evasive measures to detect crawlers, headless browsers, and bots, collecting device and browser information and sending it to an external server. Visitors are then redirected to scam sites or online casinos.
One path leads to a fake cryptocurrency trading platform that serves the DarkSword iOS exploit chain. The implant aims to capture various data from the device, including SMS, contacts, call history, voicemail, photos, location history, and files from over 25 wallet apps.
As Censys identified open directories on hosts carrying components related to DarkSword and Coruna, another iOS exploit kit, it was revealed that the DarkSword exploit kit includes two previously undocumented CVE identifiers related to WebKit engine and Core Audio framework vulnerabilities.
The operators behind these exploit kits remain unknown, but the proliferation of such kits among financially motivated actors is evident.
(This article was adapted for a WordPress platform from its original source, with additional insights from iVerify and Report URI.)



