صدر iVerify تقريراً مفصلاً حول P7 DarkSword، وهو متغير جديد من البرمجيات الخبيثة المرتبطة بسلسلة exploits DarkSword الخاصة بـ iPhone التي تم اكتشافها earlier هذا العام. تم اكتشاف المتغير خلال تحقيق في إصابة iPhonebelonging to an employee of a financial institution قبل شهرين. expands P7 DarkSword التوافق إلى iOS 18.7، up من iOS 18.6 في المتغيرات السابقة، ويتم توزيعه عبر إعلاناتmalicious في هجمات watering-hole، مما يعني أن المستخدمين يمكن أن يتم compromised simply by encountering compromised web content. Compared to previous variants, P7 reduces its on-device footprint, adds on-device Keychain and crypto-wallet theft, and introduces two-way C2 communication with attacker infrastructure. The variant improves stealth by reducing logging and process injections, uses browser storage to avoid re-exploiting devices, and enhances data-stealing capabilities. iVerify noted that the changes reflect substantial work by operators, not AI-assisted modifications, making prior indicators of compromise invalid.
P7 can extract Keychain data directly on the device before transmission and targets crypto-wallet data. Earlier this year, Google and iVerify revealed Coruna and DarkSword tools chaining iOS vulnerabilities to compromise outdated devices, prompting Apple to release updates including iOS 15.8.7, iOS 16.7.15, and iOS 18.7.7, with the latter made available to devices that could install iOS 26 to protect users who delayed updating.
المصدر: 9to5Mac · لخّصه HeadlinesBriefing