Security researchers have identified a more advanced version of the DarkSword iOS spyware framework that can steal credentials, cryptocurrency-wallet data, photos, notes and application files from compromised iPhones.
The new variant, named P7 DarkSword, also gives attackers interactive command-and-control capabilities while reducing the malware’s visible footprint. iVerify disclosed the findings on October 8, 2026, following an investigation into an infection detected on a customer’s device in August.
P7 DARKSWORD EXPANDS THE ORIGINAL SPYWARE
DarkSword is an iOS exploitation framework previously observed in attacks against devices running outdated versions of iOS. It has been associated with compromised websites that automatically deliver malicious code to vulnerable visitors.
The P7 variant retains that exploitation capability while introducing substantial improvements to its implant.
According to iVerify, P7 DarkSword:
- Removes several forms of diagnostic logging that could expose its activity.
- Reduces the number of processes into which it injects malicious code.
- Uses browser storage to prevent repeated exploitation that could crash the device or alert the victim.
- Extracts and processes keychain data directly on the compromised iPhone.
- Searches for installed cryptocurrency-wallet applications.
- Steals wallet-related information, including data from the imToken application.
- Maintains two-way communication with attacker-controlled infrastructure.
- Accepts remote commands for exploring, modifying and extracting device data.
These modifications indicate that the operators understand the original DarkSword code and are deliberately improving it for more reliable surveillance and theft.
ATTACKERS CAN ISSUE COMMANDS EVERY 15 SECONDS
P7 DarkSword injects its implant into SpringBoard, the iOS process responsible for managing the device’s home screen and several core interface functions.
The implant contacts its command-and-control server approximately every 15 seconds. Attackers can change that interval remotely to make the malware communicate more or less frequently.
Available commands allow operators to:
- List, copy, move and delete files.
- Download files from the device.
- Upload additional files or code.
- Execute JavaScript inside the implant.
- Enumerate installed applications.
- Collect device and system information.
- Search the filesystem.
- Extract photographs and Apple Notes databases.
- Identify cryptocurrency wallets.
- Obtain data stored inside application containers.
- Inspect running processes and network connections.
This design transforms the implant from a one-time information stealer into a remotely controlled surveillance platform.
WHAT SHOULD ORGANIZATIONS DO?
Organizations should treat mobile devices as security-sensitive endpoints, particularly when employees use them for authentication, cryptocurrency activity or access to corporate applications.

