---
title: "P7 DarkSword spyware variant steals Apple Keychain and crypto-wallet data from iPhones"
description: "New variant expands DarkSword's reach to iOS 18.7 and adds on-device extraction of Keychain and crypto-wallet data."
url: https://mactoreality.com/p7-darksword-spyware-variant-steals-apple-keychain-and-crypto-wallet-data-from-iphones
published: 2026-10-09T08:42:33Z
updated: 2026-10-09T08:42:33Z
author: "Mac to Reality Newsdesk"
category: Rumours
tags: ["iPhone","Privacy & security","Software"]
publisher: Mac to Reality
ai_assisted: true
apple_heat_impact: -1
---

# P7 DarkSword spyware variant steals Apple Keychain and crypto-wallet data from iPhones

*New variant expands DarkSword's reach to iOS 18.7 and adds on-device extraction of Keychain and crypto-wallet data.*

**Key points**

- iVerify discovered P7, a new DarkSword variant, on the iPhone of a financial employee in August 2026.
- P7 extracts Apple Keychain and crypto-wallet data on-device and maintains two-way communication with its C2 server.
- The spyware spreads through malicious ads in watering-hole attacks targeting unpatched iPhones up to iOS 18.7.

Security firm iVerify on 8 October [published details of P7 DarkSword](https://www.iverify.com/blog/darksword-variant-threat-research), a new iteration of the DarkSword malware targeting iPhones on iOS 18.7 and earlier. The variant was identified in August during an investigation into an infection on a finance worker’s device, iVerify told [9to5Mac](https://9to5mac.com/2026/10/08/researchers-uncover-new-darksword-spyware-variant-affecting-unpatched-iphones/).

P7 extracts Apple Keychain data into a file on the device itself rather than copying the entire Keychain database for processing elsewhere, and it can scan for and extract data from crypto-wallet apps. The malware maintains constant contact with its C2 server on a default 15-second check-in interval, allowing operators to upload files, capture photos, list applications, read Apple Notes, scan the filesystem, and access individual app containers. It achieves a smaller footprint than its predecessor through fewer process injections and reduced logging. iVerify concluded the code reflects significant manual development, not simple AI-assisted modification. The threat spreads through malicious adverts powering watering-hole attacks, with browser storage used to avoid repeat exploitation of the same device.

Earlier in 2026, Google and iVerify exposed the broader DarkSword operation and a sibling tool, Coruna, which used chains of iOS exploits to compromise unpatched systems. Apple issued fixes covering the exploited flaws. P7 does not rely on a new vulnerability; it is a revised payload deployed after a DarkSword compromise succeeds. iVerify did not disclose the specific iOS version running on the infected device.

## Sources

- [iVerify: Sleep, Beacon, Steal, Repeat - The Story of P7 DarkSword Variant](https://www.iverify.com/blog/darksword-variant-threat-research)
- [9to5Mac: Researchers uncover new DarkSword spyware variant affecting unpatched iPhones](https://9to5mac.com/2026/10/08/researchers-uncover-new-darksword-spyware-variant-affecting-unpatched-iphones/)

*This report was written by the Mac to Reality newsdesk with AI assistance from the sources listed above, under the editorial policy at https://mactoreality.com/editorial-policy.*
