P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Cybersecurity researchers reveal details of a new variant of the DarkSword iOS exploit kit called P7 DarkSword.
Intelligence analysis by Qwen 2.5 (3B)
Researchers describe a new variant of the DarkSword iOS exploit kit, P7 DarkSword, which adds crypto wallet data theft and remote commands.
A bad guy tricked into downloading a fake app that lets them spy on your phone and steal your money from your crypto wallet.
Analysis
{"heading_1":"The DarkSword Exploit Kit","paragraph_1":"DarkSword is an iOS exploit kit that has been used in attacks targeting multiple countries, including Saudi Arabia, Turkey, Malaysia, and Ukraine.","paragraph_2":"The P7 variant of DarkSword reduces its footprint on the device, adds keychain and crypto wallet theft, and includes two-way communication with the attacker's infrastructure.","paragraph_3":"The exploit chain is designed to bypass the browser sandbox and escalate privileges, allowing the implant to be injected into the SpringBoard process."}
Key points
- P7 DarkSword adds crypto wallet data theft and remote commands to the DarkSword iOS exploit kit.
- The new variant reduces its footprint on the device and uses browser localStorage to prevent re-exploitation.
- The implant is injected into the SpringBoard process and can poll for commands every 15 seconds.
The new features of P7 DarkSword make it more stealthy and harder to detect, but the core threat remains the same: it steals your data.
The new features of P7 DarkSword make it more dangerous, as it can steal more sensitive data like crypto wallet information.



