P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
iVerify details P7 DarkSword, an iOS exploit kit that steals keychains and crypto wallets and accepts remote commands.
iVerify disclosed P7 DarkSword, a DarkSword iOS exploit-kit variant that reduces its on-device footprint, extracts iCloud Keychain and cryptocurrency-wallet data on the phone, and adds two-way command-and-control. Injected into SpringBoard, the implant beacons every 15 seconds and can run shell commands and steal photos, Apple Notes, and imToken wallet data. Seen in the wild since November 2025 against iOS 18.4–18.7, it has been used in Saudi Arabia, Turkey, Malaysia, and Ukraine by operators including PARS Defense and Star Blizzard. The chain includes CVE-2025-24201 and CVE-2025-31200; Censys also linked open directories to companion kit Coruna.