iVerify today published a report detailing P7 DarkSword, a new variant of the malware associated with the DarkSword iPhone exploit chain discovered earlier this year. Here are the details.
A little context
Earlier this year, Google and iVerify revealed two sophisticated iPhone hacking tools known as Coruna and DarkSword, both of which chained together multiple iOS vulnerabilities to compromise devices with outdated system versions.
In the case of DarkSword, once an iPhone is compromised, attackers could deploy additional malware with access to sensitive data.
Coruna targeted devices running iOS 13 and iOS 17.2.1, while DarkSword targeted iPhones running iOS 18.4 and iOS 18.7.
This led Apple to release system updates for affected older iOS versions, including iOS 15.8.7, iOS 16.7.15, and iOS 18.7.7. Apple went so far as to take the unusual step of making iOS 18.7.7 available to devices that could install iOS 26, so that even users who chose not to update to the latest version of the system would remain protected from DarkSword.
At the time, Google claimed that DarkSword was being used by several commercial surveillance providers and alleged state-sponsored actors, with attacks observed against targets in Saudi Arabia, Turkey, Malaysia and Ukraine.
New DarkSword variant found in the wild
Today, iVerify announced the discovery of P7 DarkSword, a never-before-seen variant detected while investigating an infection on the iPhone of a financial institution employee just two months ago.
In further details shared with 9to5Mac, iVerify said that P7 expands compatibility to iOS 18.7, up from iOS 18.6 in the previous variant it was tracking. Other DarkSword implementations observed by Google had already supported iOS 18.7.
The company also said that the threat actor behind P7 is distributing it through malicious ads as part of watering-hole attacks, meaning victims don’t necessarily appear to be targeted individually. Instead, users can become involved in larger campaigns simply by encountering malicious or hacked web content.
From the report:
In August 2026, we investigated a DarkSword infection that turned out to be a never-before-seen variant, which we call P7 DarkSword. The name P7 comes from the threat author’s use of the file
p7_variable prefix in changes to the original DarkSword code. Compared to the variants we routinely see, P7 reduces its impact on the device, adds on-device keychain and crypto wallet theft, and adds two-way C2 communication with the attacker’s infrastructure. This post describes the investigation, the variant’s capabilities, and indicators that can be used to detect it._
The report states that P7 DarkSword improves over previous variants in three main areas: stealth, stability, and functionality. The new variant reduces logging and the number of process injections performed, uses browser storage to avoid repeatedly exploiting the same device, and expands its data theft capabilities.
iVerify also told 9to5Mac that the changes appear to reflect substantial work by operators rather than simple AI-assisted changes. The company says that P7 is much better at hiding and cleaning up its behavior, so previous indicators of compromise (IOCs) are no longer valid.
Notably, iVerify says P7 can extract keychain data directly on the iPhone before sending it to attackers, instead of copying the entire keychain database for processing elsewhere.
P7 DarkSword can also target crypto wallet data and introduces more advanced two-way communication with attackers’ command and control infrastructure.
This two-way communication also gives attackers significantly more control over an infected device. According to iVerify, P7 can receive commands to retrieve arbitrary files, upload photos, inventory installed apps, access Apple Notes databases, collect data from individual app containers, and scan the device’s filesystem.
By default, the spyware connects to the attackers’ command-and-control server every 15 seconds to receive new instructions, although this interval can be changed remotely.
It is worth noting that P7 is not a new iOS vulnerability, but rather a new version of the malware distributed after a successful compromise of DarkSword. iVerify doesn’t say what iOS version was running on the device where P7 was discovered in August.
To read iVerify’s full report, which includes technical details on how P7 works, follow this link.
It’s worth checking out on Amazon
FTC: We use automatic affiliate links that generate income. Moreover.