HeadlinesBriefing HeadlinesBriefing.com

New DarkSword Spyware P7 Variant Targets Unpatched iPhones

9to5Mac •
×

iVerify released a report detailing P7 DarkSword, a new variant of the malware associated with the DarkSword iPhone exploit chain uncovered earlier this year. The variant was discovered during an investigation of an infection on an iPhone belonging to a financial institution employee two months ago. P7 DarkSword expands compatibility to iOS 18.7, up from iOS 18.6 in earlier variants, and is distributed via malicious ads in watering-hole attacks, meaning users can be compromised simply by encountering compromised web content.

Compared to previous variants, P7 reduces its on-device footprint, adds on-device Keychain and crypto-wallet theft, and introduces two-way C2 communication with attacker infrastructure. The variant improves stealth by reducing logging and process injections, uses browser storage to avoid re-exploiting devices, and enhances data-stealing capabilities. iVerify noted the changes reflect substantial work by operators, not AI-assisted modifications, making prior indicators of compromise invalid. P7 can extract Keychain data directly on the device before transmission and targets crypto-wallet data.

Earlier this year, Google and iVerify revealed Coruna and DarkSword tools chaining iOS vulnerabilities to compromise outdated devices, prompting Apple to release updates including iOS 15.8.7, iOS 16.7.15, and iOS 18.7.7, with the latter made available to devices that could install iOS 26 to protect users who delayed updating.

Source: 9to5Mac · Summarized by HeadlinesBriefing