Skip to main content
Emerging ThreatsMalware & Ransomware

P7 DarkSword Exploit Kit Enhances iOS Data Theft Capabilities

A worn smartphone lies on a cluttered home office desk with a blank screen.

"Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said.

P7 DarkSword's on-device innovations

Researchers disclosed a previously unseen variant of the DarkSword iOS exploit kit, dubbed P7 DarkSword. The new build trims its on-device footprint and changes how sensitive data is handled: unlike prior variants that copied and exfiltrated the keychain database to external infrastructure, P7 extracts keychain data into JSON on the phone before exfiltration. The implant is injected into SpringBoard, the iOS process that manages app launches and the home screen, and uses browser localStorage to prevent re-exploitation while eliminating debug logging over HTTP requests and syslog.

Two-way C2 and the catalogue of remote actions

P7 DarkSword is not a passive data grabber. iVerify reports the implant polls for commands every 15 seconds, sends a periodic "heartbeat," enumerates installed apps, and can transmit iCloud Keychain entries, Apple Notes, Photos, and cryptocurrency wallet data. The response to the beacon can contain a broad set of instructions that execute on the victim device, including file system scans, data retrieval, and arbitrary code execution within the implant runtime.

  • execute_command — run OS commands (ls, dir, cat, mkdir, rm, echo, ps, memdump, ipconfig, netstat, whoami, etc.)
  • ls — list directory contents
  • download — read and upload a file to the C2
  • photos — upload photos from /var/mobile/Media/DCIM
  • apps — enumerate app containers and extract bundle IDs
  • exec — execute arbitrary JavaScript within the implant runtime
  • file_upload — recursively scan paths and upload matching files
  • basic_info — send device metadata to the C2
  • disk_scan — recursively scan filesystem from "/" and upload a report of files, directories, and symlinks
  • ios_app_data — find app sandbox and app-group containers and upload selected files
  • wallet_scan — scan for installed wallet apps
  • wallet_extract — extract wallet-related data for the imToken wallet app
  • memo_scan — upload Apple Notes databases
  • photo_scan — upload Apple Photos
  • sleep — modify the beacon polling interval
  • exit — halt the beacon loop and stop the implant

DarkSword, Coruna, and campaigns in the wild

DarkSword was first publicly documented earlier this March by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, and was detected in the wild in November 2025. The toolkit chains multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject payloads into SpringBoard. Researchers say the exploit chain became a commercial product that entered a second‑hand market and has been acquired by financially motivated operators and other threat actors since late 2025.

Multiple operators have used DarkSword and a companion payload kit named Coruna together. Censys described Coruna as running inside the victim's browser session after DarkSword's exploit stages and noted Coruna's wallet‑harvesting modules steal crypto recovery phrases, balances, and keystore data from iOS apps. Known uses of the kits have included attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine; named operators include a Turkish commercial surveillance vendor, PARS Defense, which used a fake Snapchat‑themed website, and a Russia‑aligned actor called Star Blizzard (aka COLDRIVER), which used fake invitation lures.

Open directories, infrastructure, and newly identified CVEs

Censys identified open directories on five hosts carrying DarkSword and Coruna components and linked infrastructure activity to device beaconing in September 2026. The five hosts enumerated by Censys include:

  • 43.134.165[.]205 — serves DS‑Fusion v1.0, a bundle including DarkSword and Coruna
  • 166.88.95[.]90 — operates as a C2 server and recorded two Chinese iOS devices polling a beacon page every three seconds on September 6, 2026
  • 23.148.212[.]237 — an analysis workspace showing exploit chain development for iOS 26 (e.g., CVE‑2026‑31001), not covered by DarkSword or Coruna
  • 47.102.192[.]23 — staging host for the Coruna kit
  • 156.239.230[.]120 — exposes the entire C2 platform and polled a device on September 15, 2026

An analysis of the production server's exploit registry revealed two previously undocumented CVEs used by DarkSword: CVE‑2025‑24201, an out‑of‑bounds write in WebKit (fixed in iOS 18.3.2 and iPadOS 18.3.2), and CVE‑2025‑31200, a memory corruption in Core Audio allowing code execution when processing a malicious audio stream (fixed in iOS 18.4.1 and iPadOS 18.4.1).

Censys also reported a likely Chinese‑speaking exploitation‑as‑a‑service operation. "The platform runs a Chinese‑speaking exploitation‑as‑a‑service operation," Censys researcher Aidan Holland said, adding that a recovered copy of the production server contained 11 victim recovery phrases, 179 device loot directories, and a 75‑account control‑plane roster. Censys further described a separate China‑based operator using the kit against its own C2 at "66ds[.]lol," adding BitKeep as a new wallet target, and tying one operator to Tencent and Shenyang hosting through a unique self‑signed certificate authority.

What this means for technologists, financial actors, and end users

  • Technologists and security teams: the change to on‑device extraction to JSON and a SpringBoard implant that polls for commands every 15 seconds means incident responders must look for indicators beyond network debug logs, inspect localStorage artifacts, and consider device‑resident JSON dumps of keychain and app data.
  • Cryptocurrency services and custodians: Censys and iVerify findings show operators harvesting recovery phrases and keystore data (Coruna) and extracting wallet data (P7), highlighting theft risk to wallets such as imToken and BitKeep identified in operator tooling.
  • End users in targeted regions: campaigns documented by GTIG, iVerify, Lookout, and Censys have targeted devices in Saudi Arabia, Turkey, Malaysia, and Ukraine and have used decoy pages (including an Apple ID sign‑in decoy) and fake themed sites to lure victims.

The record assembled by iVerify and Censys shows an exploit ecosystem that evolved from a commercial tool into a proliferating kit with reduced visibility, expanded data exfiltration, and active command channels. Attempts to add iOS 26.x support have been observed and described as unsuccessful and likely LLM‑assisted, but the leak of the kit has already driven rapid iteration by multiple operators. Whether further technical advances will close the gap to newer iOS versions or further diversify wallet targeting remains the central, unresolved question in this unfolding story.

Original report: The Hacker News — P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands