$ techbeacon▋
CVE & Exploits

New P7 DarkSword Variant Expands iOS Threat Landscape with Wallet Theft and Remote Controls

New P7 DarkSword Variant Expands iOS Threat Landscape with Wallet Theft and Remote Controls

Security researchers have uncovered a fresh iteration of the DarkSword iOS exploit kit, dubbed P7 DarkSword, that introduces a slimmer on‑device presence while extending its malicious capabilities to steal keychain entries and cryptocurrency wallet data, as well as execute remote commands.

The analysis, first reported by The Hacker News, indicates that the P7 variant diverges from earlier versions by minimizing its footprint on compromised iPhones. By reducing the number of files and processes left on the device, the kit aims to evade detection tools that look for larger, more obvious malicious artifacts.

Beyond stealth, P7 DarkSword adds two notable functionalities. First, it taps into the iOS keychain—a secure storage system for passwords, tokens, and other credentials—allowing attackers to harvest a broader set of personal data. Second, the kit specifically targets cryptocurrency wallet information, extracting private keys or seed phrases that could enable the theft of digital assets directly from the victim’s device.

In addition to data exfiltration, the kit incorporates remote command capabilities. Once installed, threat actors can issue instructions to the compromised phone, potentially installing further payloads, altering system settings, or using the device as a foothold for lateral movement within a victim’s network. This level of control aligns with trends observed in other mobile exploit kits that aim to maintain persistent, multi‑stage operations.

The emergence of P7 DarkSword underscores growing concerns among cybersecurity professionals about the evolving threat surface for iOS users. While Apple’s closed ecosystem and regular security updates have historically limited large‑scale mobile malware, sophisticated exploit kits like DarkSword demonstrate that vulnerabilities—especially those targeting zero‑day flaws—can still be weaponized. Experts advise users to keep their devices up to date, avoid installing apps from untrusted sources, and consider employing mobile security solutions that can detect anomalous behavior even when traditional signatures are absent.

Researchers are continuing to dissect the P7 code to determine its full range of capabilities and the infrastructure supporting its distribution. The findings will likely feed into broader threat‑intel sharing efforts, helping defenders anticipate future variants that may further refine stealth or expand the scope of data targeted. As the cat‑and‑mouse game between mobile security teams and threat actors persists, vigilance remains the most effective safeguard against increasingly covert iOS exploits.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related