
A new DarkSword variant called P7 steals keychain data and crypto wallets from unpatched iPhones, iVerify says
iVerify has found P7 DarkSword, a reworked variant of the leaked iPhone spyware that processes keychain data on the phone and targets crypto wallets.
The mobile security firm iVerify has published details of a new variant of the DarkSword iPhone spyware, which it calls P7 DarkSword.
In a post from its threat intelligence team on 8 October, iVerify says it found the variant in August, after an alert on one customer's iPhone that looked slightly different from its usual DarkSword detections. With the customer's consent it collected forensic data from the phone. In parallel it hunted for DarkSword infrastructure using the Validin platform, and found a domain, active around the time of the infection, hosting another version of the same spyware. The name comes from a p7_ prefix the attackers used throughout their changes to the original code.
9to5Mac, reporting the research, adds two details that are not in iVerify's post: that the phone belonged to an employee of a financial institution, and that P7 is spread through malicious advertising on compromised or malicious websites. That is a watering-hole approach, where victims are caught by visiting a page rather than being picked out individually. iVerify's post describes the victim only as a customer and does not set out how the phone was infected, so both points rest on 9to5Mac's account.
What P7 does differently
iVerify lists three changes from the variants it usually sees. For stealth, P7 drops the debug logging earlier versions sent over HTTP and to the system log, and injects into fewer processes. For stability, it uses the browser's local storage to avoid exploiting the same phone twice. For theft, it processes the keychain, where iOS keeps saved passwords and keys, on the phone itself: earlier versions copied the whole keychain database to the attackers' servers and decoded it there. It also adds two-way communication with its command server.
The implant runs inside SpringBoard, the process behind the Home Screen, and checks in with its server every 15 seconds by default, an interval the operators can change remotely. iVerify documents commands to upload photos, list installed apps, copy the Apple Notes database, scan the whole file system and fetch any file. One command extracts data from the imToken crypto wallet app by name, and another scans for other wallet apps. The post publishes network addresses and files left in /private/var/tmp that can be used to detect it.
Which iPhones are at risk?
Only phones on old software, on the evidence published. The exploit code iVerify recovered contains modules named for iOS 18.6 and iOS 18.7, which 9to5Mac describes as extending the earlier variant's reach from iOS 18.6 to iOS 18.7. iVerify names no new vulnerability. When Google's Threat Intelligence Group first documented DarkSword on 18 March, it said the chain supported iOS 18.4 to 18.7, used six vulnerabilities, and that all six were fixed by iOS 26.3.
For iPhones that stay on iOS 18, Apple's security notes for iOS 18.7.7 say it brings protection against the web attacks called DarkSword to more devices, from the iPhone XR to the iPhone 16e. It became available to them on 1 April. The newest iOS 18 release on Apple's list is iOS 18.7.10, from 17 August. Apple has said nothing about P7.
Our take
The detail that matters is in iVerify's conclusion. It sees many crude DarkSword copies made with AI tools, and says this one is different: its authors "understood the code they were modifying". A leaked exploit chain does not fade away once patched. Someone keeps maintaining it for the phones that never update, and the same toolkit sat behind a fake iPhone Duo pre-order page that ran DarkSword the moment it loaded barely a week ago. Different operators, one shared kit, which is exactly the spread Google described in March.
Decoding the keychain on the phone is a quiet but real change. A whole keychain database leaving a phone in one transfer is a lump a network monitor might notice; a small JSON file of chosen entries is far less obvious. That is our inference rather than iVerify's claim, but it fits the post's emphasis on a smaller footprint. iVerify does not say whether P7 survives a restart. Malwarebytes found no restart mechanism in the version behind the fake Duo page. Even if a restart ends a session, anything already taken has gone.
APPDOOK's reading is that there is nothing new to patch, so the job is reaching people who have not. Apple's iOS 26 releases start at the iPhone 11, so an iPhone XR or XS needs iOS 18.7.7 or later. Everything from the iPhone 11 up can run iOS 26.7.1 or iOS 27.0.1, and Settings, General, About shows which version a phone is on. Anyone who kept a crypto wallet on a phone that browsed the web while out of date should move the funds to a new wallet created on a trusted device. Google's advice for a phone that cannot be updated is Lockdown Mode. What nobody has said is how many phones P7 has reached or who runs it.
Sources
- Sleep, Beacon, Steal, Repeat - The Story of P7 DarkSword VariantiVerify, iVerify Threat Intelligence Team, 2026-10-08
Researchers uncover new DarkSword spyware variant affecting unpatched iPhones9to5Mac, Marcus Mendes, 2026-10-08
The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat ActorsGoogle Threat Intelligence Group, 2026-03-18
Fake iPhone Duo preorder scam triggers DarkSword attackMalwarebytes, 2026-09-29- About the security content of iOS 18.7.7 and iPadOS 18.7.7Apple, 2026-04-01
- Apple security releasesApple, 2026-09-28
Reporting and images linked above belong to their respective publishers and are shown from their own servers. The analysis here is our own.





