Skip to main content

Researchers uncover new DarkSword spyware variant affecting unpatched iPhones

iVerify released a report today detailing P7 DarkSword, a new variant of the malware associated with the DarkSword iPhone exploit chain uncovered earlier this year. Here are the details.

A bit of context

Earlier this year, Google and iVerify revealed two sophisticated iPhone hacking tools known as Coruna and DarkSword, both of which chained multiple iOS vulnerabilities to compromise devices running outdated system versions.

In DarkSword’s case, once an iPhone was compromised, attackers could deploy additional malware with access to sensitive data.

Coruna targeted devices running iOS 13 through iOS 17.2.1, while DarkSword affected iPhones running iOS 18.4 through iOS 18.7.

This led Apple to release system updates for the affected older iOS versions, including iOS 15.8.7, iOS 16.7.15, and iOS 18.7.7. Apple went as far as to take the unusual step of making iOS 18.7.7 available to devices that could install iOS 26, so users who elected not to update to the latest system version would also remain protected against DarkSword.

At the time, Google said DarkSword was being used by multiple commercial surveillance vendors and suspected state-sponsored actors, with attacks observed against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.

New DarkSword variant found in the wild

Today, iVerify announced the discovery of P7 DarkSword, a previously unseen variant it found while investigating an infection on the iPhone of an employee at a financial institution just two months ago.

In additional details shared with 9to5Mac, iVerify said P7 expands compatibility to iOS 18.7, up from iOS 18.6 in the earlier variant it had been tracking. Other DarkSword deployments observed by Google had already supported iOS 18.7.

The company also said the threat actor behind P7 is distributing it through malicious ads as part of watering-hole attacks, meaning victims do not necessarily appear to be individually targeted. Instead, users can be caught in broader campaigns simply by encountering malicious or compromised web content.

From the report:

In August 2026 we investigated a DarkSword infection that turned out to be a previously unseen variant, which we call P7 DarkSword. The name P7 comes from the threat actor’s use of the p7_ variable prefix in modifications to original DarkSword’s code. Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure. This post describes the investigation, the variant’s capabilities, and the indicators that can be used to detect it._

The report says that P7 DarkSword improves on earlier variants in three main areas: stealth, stability, and functionality. The new variant reduces logging and the number of process injections it performs, uses browser storage to avoid repeatedly exploiting the same device, and expands its data-stealing capabilities.

iVerify also told 9to5Mac that the changes appear to reflect substantial work by the operators rather than simple AI-assisted modifications. The company says P7 is much better at hiding itself and cleaning up its behavior, so previous indicators of compromise (IOCs) are no longer valid.

Most notably, iVerify says P7 can extract Keychain data directly on the iPhone before sending it to the attackers, instead of copying the entire Keychain database for processing elsewhere.

P7 DarkSword can also target crypto-wallet data, and introduces more advanced two-way communication with the attackers’ command-and-control infrastructure.

That two-way communication also gives attackers considerably more control over an infected device. According to iVerify, P7 can receive commands to retrieve arbitrary files, upload photos, inventory installed apps, access Apple Notes databases, collect data from individual app containers, and scan the device’s filesystem.

By default, the spyware checks in with the attackers’ command-and-control server every 15 seconds for new instructions, although that interval can be changed remotely.

It’s worth noting that P7 is not a new iOS vulnerability, but rather a new version of the malware deployed after a successful DarkSword compromise. iVerify does not say which iOS version was running on the device where P7 was discovered in August.

To read iVerify’s full report, which includes technical details on how P7 operates, follow this link.

Worth checking out on Amazon

FTC: We use income earning auto affiliate links. More.

You’re reading 9to5Mac — experts who break news about Apple and its surrounding ecosystem, day after day. Be sure to check out our homepage for all the latest news, and follow 9to5Mac on Twitter, Facebook, and LinkedIn to stay in the loop. Don’t know where to start? Check out our exclusive stories, reviews, how-tos, and subscribe to our YouTube channel

Comments

Author

Avatar for Marcus Mendes Marcus Mendes

Marcus Mendes is a Brazilian tech podcaster and journalist who has been closely following Apple since the mid-2000s.

He began covering Apple news in Brazilian media in 2012 and later broadened his focus to the wider tech industry, hosting a daily podcast for seven years.