NewsLayer.com
NewsLayer PulseLIVEBTC$83,064+0.11%ETH$2,507-0.11%SOL$109.64-0.67%XRP$1.4-0.56%DOGE$0.0859-0.33%ADA$0.2486-2.28%Total Cap$2.76T+0.02%Layer Index46 Neutral

New iPhone spyware can hunt for crypto wallets and extract their data every 15 seconds

Researchers found a new iPhone spyware variant that can remotely extract cryptocurrency wallet data and sensitive credentials from compromised devices.

CryptoSlate

Publisher

Oct 11, 2026 at 1:00 PM UTC · Updated il y a 2 heures · 3 min de lecture

New iPhone spyware can hunt for crypto wallets and extract their data every 15 seconds
Image via CryptoSlate
Traduction…

Researchers found a new iPhone spyware variant that can remotely extract cryptocurrency wallet data and sensitive credentials from compromised devices.

Security firm iVerify disclosed the malware, designated P7 DarkSword, on Oct. 8 after investigating an infection detected in August. The variant includes commands that specifically target cryptocurrency wallet apps and can collect passwords, photos, and personal information.

The discovery highlights an emerging risk for crypto holders who rely on mobile wallets: attackers who gain access to the underlying device could obtain sensitive information without exploiting a vulnerability in the wallet app itself.

How the spyware targets cryptocurrency wallets

According to iVerify's technical investigation, P7 includes two dedicated functions to identify and collect cryptocurrency-related information.

The first, wallet_scan, searches compromised devices for installed wallet applications, allowing attackers to identify potential targets.

The second, wallet_extract, is designed to collect data associated with imToken, a cryptocurrency wallet supporting multiple blockchain networks.

Together, the commands let attackers identify cryptocurrency users and retrieve wallet-related files after gaining access to their phones.