Security firm iVerify on 8 October published details of P7 DarkSword, a new iteration of the DarkSword malware targeting iPhones on iOS 18.7 and earlier. The variant was identified in August during an investigation into an infection on a finance worker’s device, iVerify told 9to5Mac.
P7 extracts Apple Keychain data into a file on the device itself rather than copying the entire Keychain database for processing elsewhere, and it can scan for and extract data from crypto-wallet apps. The malware maintains constant contact with its C2 server on a default 15-second check-in interval, allowing operators to upload files, capture photos, list applications, read Apple Notes, scan the filesystem, and access individual app containers. It achieves a smaller footprint than its predecessor through fewer process injections and reduced logging. iVerify concluded the code reflects significant manual development, not simple AI-assisted modification. The threat spreads through malicious adverts powering watering-hole attacks, with browser storage used to avoid repeat exploitation of the same device.
Earlier in 2026, Google and iVerify exposed the broader DarkSword operation and a sibling tool, Coruna, which used chains of iOS exploits to compromise unpatched systems. Apple issued fixes covering the exploited flaws. P7 does not rely on a new vulnerability; it is a revised payload deployed after a DarkSword compromise succeeds. iVerify did not disclose the specific iOS version running on the infected device.
