AI News Feed
Market watch
Cybersecurity

iVerify Finds P7 DarkSword Spyware Variant Targeting Unpatched iPhones

iVerify reports P7 DarkSword, a new iPhone spyware variant that steals Keychain and crypto-wallet data.

Earlier this year, Google and iVerify disclosed two iPhone hacking tools, Coruna and DarkSword. Both chained multiple iOS vulnerabilities to compromise devices running outdated system versions. Coruna targeted iOS 13 through iOS 17.2.1, while DarkSword affected iPhones running iOS 18.4 through iOS 18.7. Once an iPhone was compromised through DarkSword, attackers could deploy additional malware with access to sensitive data.

After those disclosures, Apple released updates for affected older iOS versions, including iOS 15.8.7, iOS 16.7.15 and iOS 18.7.7. Apple also made iOS 18.7.7 available to devices that could install iOS 26, so users who chose not to update to the latest system version would remain protected against DarkSword. Google said at the time that DarkSword was being used by multiple commercial surveillance vendors and suspected state-sponsored actors, with attacks observed against targets in Saudi Arabia, Turkey, Malaysia and Ukraine.

iVerify said P7 DarkSword was found while it investigated the August 2026 infection. The name comes from the threat actor's use of the p7_ variable prefix in modifications to the original DarkSword code. The company told 9to5Mac that P7 expands compatibility to iOS 18.7, up from iOS 18.6 in the earlier variant it had been tracking. Other DarkSword deployments observed by Google already supported iOS 18.7.

The threat actor behind P7 is distributing it through malicious ads as part of watering-hole attacks, according to iVerify. That means victims do not necessarily appear to be individually targeted; users can be caught in broader campaigns by encountering malicious or compromised web content.

In its report, iVerify said P7 improves on earlier variants in three main areas: stealth, stability and functionality. The variant reduces logging and the number of process injections it performs, uses browser storage to avoid repeatedly exploiting the same device and expands its data-stealing capabilities. iVerify also said the changes appear to reflect substantial work by the operators rather than simple AI-assisted modifications. The company said P7 is much better at hiding itself and cleaning up its behavior, so previous indicators of compromise are no longer valid.

iVerify said P7 can extract Keychain data directly on the iPhone before sending it to attackers, instead of copying the entire Keychain database for processing elsewhere. It can also target crypto-wallet data and introduces more advanced two-way communication with the attackers' command-and-control infrastructure.

That two-way communication gives attackers considerably more control over an infected device, according to iVerify. P7 can receive commands to retrieve arbitrary files, upload photos, inventory installed apps, access Apple Notes databases, collect data from individual app containers and scan the device's filesystem. By default, the spyware checks in with the attackers' command-and-control server every 15 seconds for new instructions, although that interval can be changed remotely.

iVerify said P7 is not a new iOS vulnerability but a new version of the malware deployed after a successful DarkSword compromise. The company did not say which iOS version was running on the device where P7 was discovered in August. The full report includes technical details on how P7 operates and indicators that can be used to detect it, according to iVerify.