Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.
The Hacker News
Publisher
Oct 9, 2026 at 4:29 PM UTC · 5 min de lecture
"Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday.
The name "P7" is a nod to the threat actor's use of the "p7_" variable prefix in changes made to the original DarkSword code.
DarkSword was first publicly documented earlier this March by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, detailing its ability to target iPhones running iOS versions between iOS 18.4 and 18.7. The kit was detected in the wild in November 2025.
The toolkit is engineered to chain multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject the main payload into SpringBoard, the iOS process that handles app launches and the home screen. The exploit chain is assessed to be a commercial product that somehow landed in a second-hand market, from where it was acquired by financially motivated operators and other threat actors since late 2025.
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
