Close Menu
NCIJ Network NCIJ Network
    What's Hot

    NASA Demonstrates Next-Generation Heat Shield Technologies

    October 9, 2026

    Sri Lanka elephant found with a gunshot wound. How can tuskers be protected?

    October 9, 2026

    Andy Burnham is lucky – Polanski, Farage and Badenoch all seem determined to help him | Jonathan Freedland

    October 9, 2026
    Facebook X (Twitter) Instagram
    Trending
    • NASA Demonstrates Next-Generation Heat Shield Technologies
    • Sri Lanka elephant found with a gunshot wound. How can tuskers be protected?
    • Andy Burnham is lucky – Polanski, Farage and Badenoch all seem determined to help him | Jonathan Freedland
    • Video of 2020 market fire in UAE reshared as strike on Israel – Full Fact
    • Live Updates: Human Rights Lawyer Navi Pillay Is Awarded Nobel Peace Prize
    • France, Germany try to save face on joint tank project – POLITICO
    • Ex-first minister Mark Drakeford suggests Wales Office should go
    • The Guardian view on Labour and the Greens: winning trust takes more than words | Editorial
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 9
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments6 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.

    “Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure,” iVerify said in a new report published Thursday.

    The name “P7” is a nod to the threat actor’s use of the “p7_” variable prefix in changes made to the original DarkSword code.

    DarkSword was first publicly documented earlier this March by Google Threat Intelligence Group (GTIG), iVerify, and Lookout, detailing its ability to target iPhones running iOS versions between iOS 18.4 and 18.7. The kit was detected in the wild in November 2025.

    The toolkit is engineered to chain multiple iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject the main payload into SpringBoard, the iOS process that handles app launches and the home screen. The exploit chain is assessed to be a commercial product that somehow landed in a second-hand market, from where it was acquired by financially motivated operators and other threat actors since late 2025.

    The exploit kit has been put to use in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine by multiple threat actors, including a Turkish commercial surveillance vendor named PARS Defense via a fake Snapchat-themed website and a Russia-aligned threat actor called Star Blizzard (aka COLDRIVER) using fake invitation lures.

    In August 2026, attack surface management platform Censys detailed a campaign mounted by an unknown Chinese-speaking threat actor that involved targeting Apple iOS devices with the exploit kit, in addition to serving an Apple ID decoy sign-in page.

    Cybersecurity

    As recently as last month, iVerify said it observed “multiple unsuccessful, likely LLM-assisted attempts to update the framework to support iOS 26.x,” fueled by the leak of the exploit kit shortly after its public disclosure. These variants, the mobile security company added, are focused on stability, stealth, and quality of stolen data.

    P7 DarkSword represents an evolution in these aspects by eliminating debug logging over HTTP requests and syslog and using browser localStorage to prevent re-exploitation. Unlike prior variants that copied and exfiltrated the keychain database to process on the attacker’s infrastructure, the new version extracts keychain data into JSON on the phone prior to exfiltration.

    “The implant is injected into the SpringBoard process, which handles all communication with the attacker’s infrastructure,” iVerify said.

    The latest iteration is equipped to poll for commands every 15 seconds, send a “heartbeat” message, send a list of installed applications, and transmit iCloud Keychain information and data from applications like Apple Notes, Photos, and cryptocurrency wallets.

    The response to the periodic tasking poll contains commands to be executed on the victim’s phone. This includes –

    • execute_command, to execute operating system commands like ls, dir, cat, mkdir, rm, echo, ps, memdump, ipconfig, netstat, and whoami, among others
    • ls, to list directory contents
    • download, to read a file from the device and upload it to the C2 server
    • photos, to upload photo files from “/var/mobile/Media/DCIM”
    • apps, to enumerate app containers and extract bundle IDs
    • exec, to execute arbitrary JavaScript directly inside the implant runtime
    • file_upload, to recursively scan one or more paths and upload matching files
    • basic_info, to send device metadata to the C2 server
    • disk_scan, to recursively scan the filesystem starting from “/,”, record metadata for files, directories, and symlinks, and upload the information in the form of a report
    • ios_app_data, to find app sandbox and app-group containers for requested bundle IDs and upload selected app files
    • wallet_scan, to scan for installed wallet apps
    • wallet_extract, to extract wallet-related data for imToken wallet app
    • memo_scan, to upload Apple Notes databases
    • photo_scan, to upload photos from Apple Photos
    • sleep, to modify the beacon polling interval
    • exit, to halt the beacon loop and stop the implant

    The disclosure comes as Censys said it identified open directories on five hosts carrying components related to DarkSword and Coruna, another iOS exploit kit uncovered this year as weaponized in attacks aimed at iPhone models running iOS versions between 13.0 and 17.2.1.

    “Coruna is the companion payload kit the same ecosystem distributes,” Censys said. “Its stages run inside the victim’s browser session after DarkSword’s exploit stages land, and its wallet-harvesting modules steal crypto recovery phrases, balances, and keystore data from iOS apps. Operators run DarkSword and Coruna together against their own C2 infrastructure.”

    The five hosts are listed below –

    • 43.134.165[.]205, which serves DS-Fusion v1.0 (aka DarkSword Fusion), a combined package that includes both DarkSword and Coruna in a single bundle
    • 166.88.95[.]90, which operates as a C2 server of the implant and has recorded two real Chinese iOS devices (183.154.173[.]30 and 182.239.114[.]223) polling a beacon page every three seconds for several hours on September 6, 2026
    • 23.148.212[.]237, which serves as an analysis workspace that shows the operator developing exploit chains for iOS 26 (such as for CVE-2026-31001), which are not covered by DarkSword or Coruna.
    • 47.102.192[.]23, which serves as a staging host for the Coruna kit
    • 156.239.230[.]120, which exposes the entire C2 platform and has been observed polling a device on September 15, 2026
    Cybersecurity

    An analysis of the production server’s exploit registry has revealed that the DarkSword exploit kit comprises two CVE identifiers not previously documented –

    • CVE-2025-24201, an out-of-bounds write vulnerability in the WebKit engine that could allow an attacker to break out of the Web Content sandbox (Fixed in iOS 18.3.2 and iPadOS 18.3.2)
    • CVE-2025-31200, a memory corruption vulnerability in the Core Audio framework that allows code execution when processing an audio stream in a maliciously crafted media file (Fixed in iOS 18.4.1 and iPadOS 18.4.1)

    It’s suspected that the open-directory cluster and the 156.239.230[.]120 platform are run by a Chinese-speaking threat actor with an aim to conduct cryptocurrency wallet theft. That said, exactly who is behind is unknown.

    “The platform runs a Chinese-speaking exploitation-as-a-service operation,” Censys researcher Aidan Holland said. “The admin panel exposes an agent/reseller model, and a copy of the production server recovered 11 victim recovery phrases, 179 device loot directories, and a 75-account control-plane roster.”

    Censys said it also detected a separate China-based operator running the same kit in the wild against its own C2 server at “66ds[.]lol,” while including a new cryptocurrency wallet target (BitKeep) not present in the open-directory set. The findings once again highlight the proliferation of the kit among financially motivated actors.

    “The operator behind it sits on Tencent and Shenyang hosting, tied to the operator through a unique self-signed certificate authority,” Censys said.

    adds Commands Crypto DarkSword data exploit iOS kit remote theft Wallet
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Germany arrests alleged core Qilin ransomware member after extradition

    Google Domains Impacted by Recent ccTLD Hijacks

    Max severity SonicWall SMA1000 flaw now exploited in attacks

    In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

    How much nature is left? Interview with Nature Data Lab’s Karl Burkart

    Firmus: Nvidia-backed data centre firm scraps IPO as AI valuation concerns deepen

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    NASA Demonstrates Next-Generation Heat Shield Technologies

    October 9, 2026

    Sri Lanka elephant found with a gunshot wound. How can tuskers be protected?

    October 9, 2026

    Andy Burnham is lucky – Polanski, Farage and Badenoch all seem determined to help him | Jonathan Freedland

    October 9, 2026

    Video of 2020 market fire in UAE reshared as strike on Israel – Full Fact

    October 9, 2026
    Latest Posts

    Reform donor Arron Banks urged to set out extent of surveillance of journalists | Arron Banks

    August 10, 2026

    The Canadian Secessionists Who Love Trump

    August 10, 2026

    How ‘Harry Potter’ Fans Protected Dobby’s Grave From the Path of a U.K.-Ireland Power Line

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    NASA Demonstrates Next-Generation Heat Shield Technologies

    October 9, 2026

    Sri Lanka elephant found with a gunshot wound. How can tuskers be protected?

    October 9, 2026

    Andy Burnham is lucky – Polanski, Farage and Badenoch all seem determined to help him | Jonathan Freedland

    October 9, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.