Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.

“Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure,” iVerify said in a new report published Thursday.

The name “P7” is a nod to the threat actor’s use of the “p7_” variable prefix in changes made to the original DarkSword code.

DarkSword was first publicly documented earlier this March by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, detailing its ability to target iPhones running iOS versions between iOS 18.4 and 18.7. The kit was detected in the wild in November 2025.

The toolkit is engineered to chain multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject the main payload into SpringBoard, the iOS process that handles app launches and the home screen. The exploit chain is assessed to be a commercial product that somehow landed in a second-hand market, from where it was acquired by financially motivated operators and other threat actors since late 2025.

The exploit kit has been put to use in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine by multiple threat actors, including a Turkish commercial surveillance vendor named PARS Defense via a fake Snapchat-themed website and a Russia-aligned threat actor called Star Blizzard (aka COLDRIVER) using fake invitation lures.

In August 2026, attack surface management platform Censys detailed a campaign mounted by an unknown Chinese-speaking threat actor that involved targeting Apple iOS devices with the exploit kit, in addition to serving an Apple ID decoy sign-in page.

Cybersecurity

As recently as last month, iVerify said it observed “multiple unsuccessful, likely LLM-assisted attempts to update the framework to support iOS 26.x,” fueled by the leak of the exploit kit shortly after its public disclosure. These variants, the mobile security company added, are focused on stability, stealth, and quality of stolen data.

P7 DarkSword represents an evolution in these aspects by eliminating debug logging over HTTP requests and syslog and using browser localStorage to prevent re-exploitation. Unlike prior variants that copied and exfiltrated the keychain database to process on the attacker’s infrastructure, the new version extracts keychain data into JSON on the phone prior to exfiltration.

“The implant is injected into the SpringBoard process, which handles all communication with the attacker’s infrastructure,” iVerify said.

The latest iteration is equipped to poll for commands every 15 seconds, send a “heartbeat” message, send a list of installed applications, and transmit iCloud Keychain information and data from applications like Apple Notes, Photos, and cryptocurrency wallets.

The response to the periodic tasking poll contains commands to be executed on the victim’s phone. This includes –

  • execute_command, to execute operating system commands like ls, dir, cat, mkdir, rm, echo, ps, memdump, ipconfig, netstat, and whoami, among others
  • ls, to list directory contents
  • download, to read a file from the device and upload it to the C2 server
  • photos, to upload photo files from “/var/mobile/Media/DCIM”
  • apps, to enumerate app containers and extract bundle IDs
  • exec, to execute arbitrary JavaScript directly inside the implant runtime
  • file_upload, to recursively scan one or more paths and upload matching files
  • basic_info, to send device metadata to the C2 server
  • disk_scan, to recursively scan the filesystem starting from “/,”, record metadata for files, directories, and symlinks, and upload the information in the form of a report
  • ios_app_data, to find app sandbox and app-group containers for requested bundle IDs and upload selected app files
  • wallet_scan, to scan for installed wallet apps
  • wallet_extract, to extract wallet-related data for imToken wallet app
  • memo_scan, to upload Apple Notes databases
  • photo_scan, to upload photos from Apple Photos
  • sleep, to modify the beacon polling interval
  • exit, to halt the beacon loop and stop the implant

The disclosure comes as Censys said it identified open directories on five hosts carrying components related to DarkSword and Coruna, another iOS exploit kit uncovered this year as weaponized in attacks aimed at iPhone models running iOS versions between 13.0 and 17.2.1.

“Coruna is the companion payload kit the same ecosystem distributes,” Censys said. “Its stages run inside the victim’s browser session after DarkSword’s exploit stages land, and its wallet-harvesting modules steal crypto recovery phrases, balances, and keystore data from iOS apps. Operators run DarkSword and Coruna together against their own C2 infrastructure.”

The five hosts are listed below –

  • 43.134.165[.]205, which serves DS-Fusion v1.0 (aka DarkSword Fusion), a combined package that includes both DarkSword and Coruna in a single bundle
  • 166.88.95[.]90, which operates as a C2 server of the implant and has recorded two real Chinese iOS devices (183.154.173[.]30 and 182.239.114[.]223) polling a beacon page every three seconds for several hours on September 6, 2026
  • 23.148.212[.]237, which serves as an analysis workspace that shows the operator developing exploit chains for iOS 26 (such as for CVE-2026-31001), which are not covered by DarkSword or Coruna.
  • 47.102.192[.]23, which serves as a staging host for the Coruna kit
  • 156.239.230[.]120, which exposes the entire C2 platform and has been observed polling a device on September 15, 2026
Cybersecurity

An analysis of the production server’s exploit registry has revealed that the DarkSword exploit kit comprises two CVE identifiers not previously documented –

  • CVE-2025-24201, an out-of-bounds write vulnerability in the WebKit engine that could allow an attacker to break out of the Web Content sandbox (Fixed in iOS 18.3.2 and iPadOS 18.3.2)
  • CVE-2025-31200, a memory corruption vulnerability in the Core Audio framework that allows code execution when processing an audio stream in a maliciously crafted media file (Fixed in iOS 18.4.1 and iPadOS 18.4.1)

It’s suspected that the open-directory cluster and the 156.239.230[.]120 platform are run by a Chinese-speaking threat actor with an aim to conduct cryptocurrency wallet theft. That said, exactly who is behind is unknown.

“The platform runs a Chinese-speaking exploitation-as-a-service operation,” Censys researcher Aidan Holland said. “The admin panel exposes an agent/reseller model, and a copy of the production server recovered 11 victim recovery phrases, 179 device loot directories, and a 75-account control-plane roster.”

Censys said it also detected a separate China-based operator running the same kit in the wild against its own C2 server at “66ds[.]lol,” while including a new cryptocurrency wallet target (BitKeep) not present in the open-directory set. The findings once again highlight the proliferation of the kit among financially motivated actors.

“The operator behind it sits on Tencent and Shenyang hosting, tied to the operator through a unique self-signed certificate authority,” Censys said.



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here