A new DarkSword variant, called P7, has been discovered on unpatched iPhones.
P7 expands compatibility to iOS 18.7 and uses watering-hole attacks via malicious ads.
The spyware can steal Keychain data and crypto-wallet information and communicates with attackers every 15 seconds by default.
Apple has previously issued patches for related DarkSword variants, but P7 targets devices that haven’t updated.
Quick read · 1 min
A new DarkSword spyware variant called P7 has been found affecting iPhones that aren’t fully updated. It can steal Keychain data and crypto-wallet information and communicates with attackers every 15 seconds on a built-in control channel. P7 uses watering-hole attacks, meaning simply visiting a compromised site can trigger the infection.
What this means for you: keep your iPhone updated with the latest iOS, use automatic updates, and be careful with web ads and unfamiliar sites. If you’re concerned you might be infected, back up data and follow Apple’s security guidance.
Update your device
Enable automatic updates
Be mindful of suspicious sites and ads
The latest security finding is a new variant of the DarkSword spyware, labeled P7 by researchers at iVerify. It was uncovered while examining an infection on an iPhone two months ago and expands the reach of the DarkSword family to iOS 18.7, in addition to versions the chain already targeted. This makes unpatched devices more vulnerable than before.
P7 stands out for its on-device capabilities. It not only reduces its footprint and logging to stay hidden, but it also adds on-device theft of Keychain data and crypto-wallet information. It also introduces more capable two-way communication with the attackers’ control infrastructure, allowing commands to be sent back and forth directly from the phone.
Researchers describe P7 as a step up in stealth, stability, and functionality compared with earlier DarkSword variants. The malware uses watering-hole tactics, meaning people can be infected simply by visiting malicious or compromised websites or ad networks, rather than targeting a specific person. The attackers can then trigger a range of actions on the device through the command-and-control channel.
When infected, the iPhone communicates with the attacker’s server at short intervals, about every 15 seconds by default. That clock can be adjusted remotely, giving operators tighter control over what data is collected and when to pull new instructions. The key changes in P7 include direct extraction of Keychain data on the device, rather than transferring the whole Keychain database for processing, and the ability to reach crypto-wallet data directly from the device.
Google and iVerify had previously highlighted Coruna and DarkSword as tools used by multiple surveillance vendors and suspected state actors. Apple had rolled out system updates to patch older DarkSword-related vulnerabilities and even made certain older iOS builds available to protect devices that choose not to upgrade to the latest version. P7 demonstrates how attackers keep evolving once a foothold is gained and why staying updated matters more than ever.
01
What this means for iPhone users
In plain terms, if your iPhone isn’t up to date, you could be at greater risk of a stealthy attack that can steal sensitive data stored on your device and push commands to exfiltrate more information. Keychain data can include passwords and other credentials, while crypto-wallet data could involve your digital assets. The best protection remains: install the latest iOS updates when they become available and consider turning on automatic updates so you don’t miss critical security fixes.
02
How P7 spreads and why it’s concerning
P7 uses watering-hole distribution, which targets broad groups rather than individuals. By compromising legitimate or trusted sites and ad networks, attackers can trigger an infection by simply visiting a compromised page. This makes it harder to avoid without general safe browsing habits and up-to-date protections.
03
What Apple and researchers are saying
Apple has historically issued patches for related exploits when they become publicly known. Researchers stress that P7 is not a new vulnerability itself but a new variant of an existing spyware family. It highlights the ongoing tug-of-war between attackers refining their tools and defenders pushing updates to close the door.
04
What you can do now
– Ensure your iPhone runs the latest iOS version and enable automatic updates. – Be cautious about visiting questionable sites or clicking on ads, especially from sources you don’t recognize. – If you suspect an infection, back up data, reset the device if necessary, and consult Apple’s guidance on malware and device security.
It’s a new variant of the DarkSword spyware that can steal Keychain data and crypto-wallet information and communicates with attackers via a bidirectional command-and-control channel.
How does it spread?
Through watering-hole attacks that compromise websites or ads; visiting these sites can trigger the infection on unpatched iPhones.
What should I do right away?
Update iOS to the latest version, turn on automatic updates, and practice cautious browsing to reduce exposure to compromised sites.