P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
AI Image

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

The Hacker News • • technology

Key Points:

  • Cybersecurity researchers have revealed a new variant of the DarkSword iOS exploit kit, named P7 DarkSword, which minimizes its device footprint and adds capabilities to steal keychain and crypto-wallet data while enabling two-way command and control (C2) communication.
  • Originally detected in November 2025 and targeting iOS versions 18.4 to 18.7, DarkSword exploits multiple iOS vulnerabilities to escape the browser sandbox and escalate privileges, with its use documented in attacks against countries including Saudi Arabia, Turkey, Malaysia, and Ukraine.
  • The P7 variant improves stealth by removing debug logging and extracting sensitive data on the device before exfiltration, enabling attackers to execute various commands remotely, including file downloads, photo uploads, wallet data extraction, and execution of arbitrary JavaScript.
  • The exploit kit has been distributed via compromised domains, such as a re-registered Czech e-commerce analytics site, which delivers malicious JavaScript to infect visitors and redirect them to scam or cryptocurrency trading sites serving the DarkSword payload.
  • Analysis by Censys and iVerify uncovered related infrastructure hosting combined DarkSword and Coruna payloads, new undocumented CVEs exploited by DarkSword, and indications of Chinese-speaking threat actors operating exploitation-as-a-service platforms focused on cryptocurrency wallet theft.

Trending Business

Trending Technology

Trending Health