Back to Newsroom
Threat Intel

P7 DarkSword iOS Exploit Kit Adds Remote Control and Crypto Wallet Theft

A new DarkSword variant turns compromised iPhones into remotely tasked implants that harvest Keychain and wallet data — and it is now spreading through a hijacked analytics domain.

P7 DarkSword iOS Exploit Kit Adds Remote Control and Crypto Wallet Theft

P7 DarkSword: the iOS exploit kit is now stealing wallets and taking orders

A new build of the DarkSword iOS exploit kit, tracked by researchers as P7 DarkSword, has turned a one-shot data grabber into a remotely controlled implant. The variant is quieter on the device, harvests Keychain and crypto-wallet data locally before sending it out, and now polls its operators for commands — giving attackers an ongoing foothold on compromised iPhones.

What happened

DarkSword first surfaced publicly in March 2026 as a chain of iOS vulnerabilities that escapes Safari's sandbox, gains kernel read/write and injects a payload into SpringBoard, the process that runs the iPhone home screen. It targets iOS 18.4 through 18.7 and has been seen in the wild since late 2025. Researchers believe it started life as a commercial product before leaking onto a second-hand market, where both financially motivated crews and state-aligned actors picked it up.

The new P7 variant (named after the p7_ prefix its authors added to the code) changes three things:

  • Less noise. Debug logging over HTTP and syslog is gone, and browser localStorage is used to avoid re-infecting the same device.
  • On-device collection. Instead of shipping the raw Keychain database home, the implant parses Keychain items into JSON on the phone first.
  • Two-way C2. The implant checks in roughly every 15 seconds and accepts tasking: run shell commands, list and download files, crawl the filesystem, enumerate installed apps and pull their sandbox data, dump Apple Notes and Photos, scan for wallet apps and extract data from specific wallets, or change its beacon interval.

Separately, researchers found DarkSword being delivered through an expired analytics domain (ecomtrack[.]io) that attackers re-registered in September 2026. Online shops that never removed the old tracking tag began loading attacker-controlled JavaScript, which fingerprints visitors, hides from crawlers and headless browsers, and redirects some of them — in at least one path, to a fake crypto-trading site that serves the full iOS exploit chain. That build targets SMS, contacts, call history, location, health data, saved Wi-Fi passwords and more than 25 wallet apps.

Infrastructure research also turned up open directories on five hosts tied to DarkSword and its companion kit Coruna (which targets older iOS 13.0–17.2.1), including a bundled "DS-Fusion" package, live C2 servers and a workspace where an operator appears to be developing chains for iOS 26. Analysis of the kit's exploit registry identified two previously undocumented CVEs in the chain: CVE-2025-24201 (WebKit sandbox escape, fixed in iOS 18.3.2) and CVE-2025-31200 (Core Audio memory corruption, fixed in iOS 18.4.1).

Researchers suspect at least one cluster is a Chinese-speaking "exploitation-as-a-service" operation with a reseller model focused on crypto theft, but who is behind it has not been confirmed. A separate China-based operator was also seen running the kit against its own infrastructure. Researchers also report many broken, likely LLM-assisted attempts to port the kit to iOS 26 — so far without evidence of success.

Why it matters

  • Patch gaps are the attack surface. Every exploit in this chain has a fix. Devices stuck on iOS 18.x — often unmanaged personal phones used for work — are the ones at risk.
  • Web supply chain risk is real. A forgotten third-party script on a store page became a delivery channel for a mobile exploit chain. If your site still loads tags from vendors that no longer exist, someone else may own that domain.
  • Persistent access changes the impact. With live tasking, a single compromise can lead to ongoing collection of credentials, notes, photos and wallet secrets — not just a single dump.
  • The kit is spreading. Leaked tooling, resellers and copycat builds mean more operators, more lures and more targets over time.

What to do

  1. Update iPhones and iPads to the latest iOS/iPadOS and enforce a minimum OS version via MDM. Treat devices that can't upgrade as untrusted for corporate data.
  2. Enable Lockdown Mode for high-risk users (executives, finance, crypto/treasury staff, journalists).
  3. Audit third-party scripts on your websites. Remove tags for discontinued services, check that every external script domain is still owned by the vendor, and use a Content Security Policy and Subresource Integrity where possible.
  4. Block and hunt for known indicators in DNS and proxy logs, e.g. ecomtrack[.]io, chainmate[.]top, mertio[.]cc, 66ds[.]lol and the .fit domains used for exfiltration.
  5. Protect crypto assets. Keep significant holdings in hardware wallets; if a phone with a wallet app may have been exposed, move funds to a new wallet created on a clean device.
  6. Rotate credentials stored in the iCloud Keychain of any device suspected of compromise, and review sign-in activity for linked accounts.

Need to know whether your web properties still load scripts from abandoned domains? 4Tify's attack-surface monitoring flags stale third-party dependencies before attackers do.


Original reporting: The Hacker News, drawing on research by iVerify, Censys and Report URI (Scott Helme). This is 4Tify's independent summary and analysis.

SHARE