phan mem gian diep iPhone.png
The P7 DarkSword spyware variant introduces new capabilities targeting cryptocurrency wallet data on compromised iPhones. Photo: 9to5Mac.

The emergence of P7 DarkSword, a more sophisticated variant of the spyware linked to earlier iPhone attacks, suggests that cybercriminals are continuing to develop their tools even after Apple has released security patches.

The new malware is designed to operate more discreetly, steal sensitive information and give attackers greater remote control over compromised devices.

More concerningly, P7 DarkSword can spread through malicious advertisements, potentially exposing users who are not specifically targeted by the attackers.

New DarkSword variant puts unpatched iPhones at risk

In a report published on October 9, cybersecurity company iVerify disclosed the discovery of P7 DarkSword, a previously undocumented malware variant associated with the DarkSword iPhone exploit chain.

The discovery followed an investigation into an infected iPhone belonging to an employee at a financial institution in August 2026.

Earlier this year, Google and iVerify revealed two sophisticated iPhone hacking toolkits, Coruna and DarkSword.

Both exploit chains combine multiple vulnerabilities in Apple's iOS operating system to compromise devices running outdated software.

Coruna targeted devices running iOS 13 through iOS 17.2.1, while DarkSword affected iPhones running iOS 18.4 through iOS 18.7.

Once an attacker successfully compromises a device, additional malware can be deployed to collect sensitive information stored on the iPhone.

In response to these threats, Apple released security updates for affected older versions of iOS, including iOS 15.8.7, iOS 16.7.15 and iOS 18.7.7.

Notably, Apple took the relatively unusual step of making iOS 18.7.7 available even to devices capable of installing iOS 26.

The move was intended to protect users who had not yet upgraded to the latest operating system from attacks exploiting the DarkSword vulnerabilities.

According to information previously published by Google, DarkSword has been used by multiple commercial surveillance vendors.

Researchers also suspect that some state-sponsored threat actors have been involved in exploiting the toolkit.

Attacks have been observed in Saudi Arabia, Turkey, Malaysia and Ukraine.

P7 DarkSword becomes harder to detect and more capable of stealing data

According to iVerify, P7 DarkSword introduces three significant improvements over earlier variants: greater stealth, improved stability and expanded functionality.

The new version reduces its footprint on infected devices by limiting logging activity and performing fewer code injections into running processes.

It also uses browser storage to avoid repeatedly exploiting the same device.

This approach helps reduce unusual activity that might otherwise trigger security monitoring tools.

P7 also expands its compatibility with iOS versions.

In additional information shared with technology publication 9to5Mac, iVerify said the new variant supports iOS 18.7, whereas the earlier version tracked by the company was compatible only up to iOS 18.6.

Other DarkSword campaigns previously observed by Google had already demonstrated compatibility with iOS 18.7.

A more serious concern lies in P7's expanded data collection capabilities.

Instead of copying Apple's entire Keychain database and transferring it elsewhere for processing, P7 can extract information directly from the Keychain on the compromised iPhone before sending the collected data to the attackers.

Keychain is Apple's system for managing sensitive information, including passwords, authentication credentials and other security-related data.

Unauthorized access to this system could therefore increase the risk of account information being exposed, depending on the specific data the malware manages to retrieve.

P7 DarkSword also introduces capabilities designed to target cryptocurrency wallet data.

This is a particularly significant development because information associated with digital wallets can provide attackers with opportunities for direct financial gain.

Attackers can remotely control infected iPhones through C2 servers

One of P7 DarkSword's most important upgrades is its ability to establish two-way communication with the attackers' command-and-control (C2) infrastructure.

Through this connection, the malware can do more than transmit stolen information.

It can also receive new instructions and carry out specific actions on an infected device.

According to iVerify, P7 can be instructed to retrieve arbitrary files, upload photographs to attacker-controlled servers, generate lists of installed applications, access Apple Notes databases, collect information from individual application storage containers and scan the device's file system.

By default, the spyware contacts its C2 server every 15 seconds to check for new instructions.

However, attackers can remotely adjust this interval, allowing them to change how the malware operates depending on their objectives and circumstances.

iVerify said the improvements seen in P7 appear to reflect substantial development work by its operators rather than minor changes made with the assistance of artificial intelligence (AI).

The new variant is more effective at concealing its activity and removing traces of its operations.

As a result, many indicators of compromise (IOCs) that were useful for detecting earlier DarkSword versions may no longer be reliable.

This makes identifying infections more challenging for security teams relying on previously established detection methods.

What iPhone users should do to stay protected

Importantly, P7 DarkSword is not an entirely new vulnerability in iOS.

It is a new version of the malware deployed after attackers have successfully compromised a device through the existing DarkSword exploit chain.

In its report, iVerify did not disclose the specific iOS version running on the infected iPhone discovered during the August 2026 investigation.

The discovery of P7 therefore does not mean that every iPhone faces the same level of risk.

Exposure depends on several factors, including the operating system version, whether the device has received relevant security updates and whether it has encountered malicious online content.

To reduce the risk of infection, iPhone users should install the latest iOS updates and security patches available for their devices.

Owners of older iPhone models should also pay attention to security updates released specifically for the operating system versions they continue to use.

Users are advised to exercise caution when encountering suspicious advertisements, unfamiliar websites or webpages that show signs of compromise.

According to iVerify, the group behind P7 has been distributing the malware through malicious advertisements as part of so-called "watering-hole" attacks.

This technique involves targeting websites that a particular group of users is likely to visit, rather than attempting to compromise each victim individually.

As a result, attackers do not necessarily need to identify and target a specific iPhone owner.

Simply encountering malicious or compromised web content during such a campaign could expose a user to an attack if their device meets the conditions required for exploitation.

The discovery of P7 DarkSword highlights the continuing risks faced by devices running outdated software, even after security vulnerabilities have been publicly disclosed and patched.

Hai Phong