Mobile Tech
Unpatched iPhones at Risk: Discovering the DarkSword Spyware Variant
A recent report by iVerify sheds light on P7 DarkSword, a new variant of the malware associated with the DarkSword iPhone exploit chain that was uncovered earlier this year. Let’s delve into the details.
Understanding the Context
In the past year, Google and iVerify disclosed two advanced iPhone hacking tools named Coruna and DarkSword. These tools exploited multiple iOS vulnerabilities to compromise devices running outdated system versions.
DarkSword, in particular, allowed attackers to deploy additional malware once an iPhone was compromised, gaining access to sensitive data.
Coruna targeted devices running iOS 13 through iOS 17.2.1, while DarkSword impacted iPhones running iOS 18.4 through iOS 18.7.
As a response, Apple issued system updates for the affected older iOS versions, including iOS 15.8.7, iOS 16.7.15, and iOS 18.7.7. Notably, Apple even made iOS 18.7.7 available to devices capable of installing iOS 26 to ensure protection against DarkSword for users who chose not to update immediately.
Google mentioned that DarkSword was utilized by various commercial surveillance vendors and suspected state-sponsored actors, with targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.
Discovery of a New DarkSword Variant
Recently, iVerify announced the identification of P7 DarkSword, a previously unseen variant discovered during an investigation into an infection on an employee’s iPhone at a financial institution just two months ago.
Further insights shared with 9to5Mac revealed that P7 extends compatibility to iOS 18.7, an upgrade from iOS 18.6 in the earlier tracked variant. Previous DarkSword deployments observed by Google already supported iOS 18.7.
According to iVerify, the threat actor behind P7 distributes it through malicious ads in watering-hole attacks, where victims might not be individually targeted but could fall prey to broader campaigns by encountering compromised web content.
The report highlights:
In August 2026, we investigated a DarkSword infection that turned out to be a previously unseen variant, which we refer to as P7 DarkSword. The designation “P7” originates from the threat actor’s utilization of the
p7_variable prefix in modifications to the original DarkSword code. Compared to typical variants, P7 reduces its on-device footprint, includes on-device keychain and crypto-wallet theft, and integrates two-way communication with the attacker’s infrastructure. This post outlines the investigation, the variant’s capabilities, and the indicators for detection.
The report highlights that P7 DarkSword enhances previous variants in stealth, stability, and functionality. The new variant minimizes logging and process injections, uses browser storage to avoid repeated exploitation of the same device, and enhances data theft capabilities.
iVerify also mentioned to 9to5Mac that the changes signify substantial effort by the operators rather than simple AI-assisted alterations. P7 exhibits improved concealment and behavior cleanup, rendering previous indicators of compromise (IOCs) ineffective.
Notably, P7 can extract Keychain data directly on the iPhone before transmitting it to the attackers, rather than copying the entire Keychain database for processing elsewhere.
Additionally, P7 DarkSword can target crypto-wallet data and introduces advanced two-way communication with the attackers’ command-and-control infrastructure.
This two-way communication grants attackers greater control over the infected device. iVerify mentioned that P7 can receive commands to retrieve files, upload photos, list installed apps, access Apple Notes databases, extract data from individual app containers, and scan the device’s filesystem.
By default, the spyware communicates with the attackers’ command-and-control server every 15 seconds for new directives, with the ability to remotely adjust this interval.
It’s important to note that P7 isn’t a new iOS vulnerability but a revised version of the malware deployed post a successful DarkSword compromise. iVerify didn’t disclose the iOS version on the device where P7 was detected in August.
For a comprehensive read of iVerify’s report, including technical insights on P7’s operations, refer to this link.
Recommended on Amazon


FTC: We use income earning auto affiliate links. More.

-
Facebook12 months agoEU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
-
Facebook12 months agoWarning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
-
Facebook10 months agoFacebook’s New Look: A Blend of Instagram’s Style
-
Facebook12 months agoFacebook Compliance: ICE-tracking Page Removed After US Government Intervention
-
Facebook10 months agoFacebook and Instagram to Reduce Personalized Ads for European Users
-
Facebook12 months agoInstaDub: Meta’s AI Translation Tool for Instagram Videos
-
Facebook10 months agoReclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
-
Apple12 months agoMeta discontinues Messenger apps for Windows and macOS

