P7 DarkSword variant targets unpatched iPhones via malicious ads

Security firm iVerify has identified P7 DarkSword, a new variant of the iPhone exploit chain that targets devices running iOS 18.7. Discovered in August 2026 on a financial employee’s phone, this malware uses watering-hole attacks via malicious ads to infect users. It features enhanced stealth, direct on-device Keychain theft, and two-way command-and-control communication, allowing attackers to steal photos, notes, and crypto-wallet data.
Key points
- P7 DarkSword is a new variant of the DarkSword exploit chain, discovered by iVerify in August 2026.
- The malware targets iPhones running iOS 18.7, expanding the range of affected versions from previous iterations.
- Distribution occurs through watering-hole attacks using malicious ads, meaning victims are not necessarily individually targeted.
- P7 reduces its on-device footprint and uses browser storage to avoid repeated exploitation of the same device.
- It enables direct on-device extraction of Keychain data and crypto-wallet information, rather than copying entire databases.
- The variant supports two-way command-and-control communication, checking in every 15 seconds for new instructions.
Background
Earlier this year, Google and iVerify revealed the Coruna and DarkSword exploit chains, which targeted outdated iOS versions. Apple responded by releasing security updates for older systems, including iOS 18.7.7, to protect users who had not upgraded to the latest OS. P7 DarkSword is a subsequent evolution of this threat, not a new vulnerability, but a modified malware payload deployed after a successful compromise.
How outlets are covering it
9to5Mac and iVerify emphasize the technical advancements of P7, such as reduced logging and improved stealth, noting that previous indicators of compromise are no longer valid. Bhaskar English focuses on the practical risks to users, highlighting the theft of passwords and private data, and provides protective advice. While all sources agree on the threat’s capabilities, 9to5Mac and iVerify attribute the changes to substantial operator work rather than AI-assisted modifications, a detail not mentioned by Bhaskar English.
Why it matters
The discovery of P7 DarkSword highlights the ongoing risk to unpatched iPhones, even after Apple’s previous security updates. The shift to watering-hole attacks via malicious ads means that any user on an affected iOS version could be compromised without being a specific target. The enhanced capabilities for stealing sensitive data, including crypto-wallet information, underscore the need for immediate software updates and cautious browsing habits.
What to watch
Users should ensure their iPhones are updated to the latest iOS version to mitigate the risk of DarkSword exploits. Security firms may continue to monitor for new variants and distribution methods. Apple has not yet issued an official statement regarding P7 DarkSword, but users are advised to avoid suspicious links and untrusted websites.
- Researchers uncover new DarkSword spyware variant affecting unpatched iPhones 9to5Mac
- Sleep, Beacon, Steal, Repeat - The Story of P7 DarkSword Variant iVerify
- DarkSword iOS Exploit Platform Uses Coruna Malware to Steal Crypto Wallet Recovery Phrases CyberSecurityNews
- DarkSword returns with a nastier trick that lets hackers steal your iPhone data in real time Digital Trends
- iPhone users beware! New spyware can steal passwords and data: What is 'P7 DarkSword' malware, and how to s... Bhaskar English
Want the full story? Read the original reporting
Read on 9to5Mac