Skip to content

P7 DarkSword iOS exploit kit adds keychain, crypto-wallet theft

iVerify documented P7, a reworked DarkSword iOS exploit kit that extracts Keychain data and imToken wallet contents and adds two-way C2; IOCs published.

Published 3 min read

iVerify has documented P7 DarkSword, a reworked variant of the DarkSword iOS exploit kit that pulls Keychain data and cryptocurrency-wallet contents off compromised iPhones and adds a two-way command-and-control channel. iVerify's threat-research writeup is the primary source, published October 11; The Hacker News corroborated it with ecosystem detail from Report URI and Censys.

What P7 changes

iVerify says the "P7" label comes from the operator's use of a p7_ variable prefix in modifications to the original DarkSword code. Against earlier builds, P7:

  • Converts Keychain contents to JSON on-device before exfiltration, instead of copying the Keychain database off the phone.
  • Adds a wallet_extract handler that "Extracts wallet-related data for imToken wallet app" and a wallet_scan handler that enumerates installed wallet apps.
  • Beacons to its C2 every 15 seconds (configurable via a sleep command) and exposes a command dispatcher covering file operations, process listing, Photos, installed-app inventory, Notes scraping, and arbitrary exec/eval.
  • Drops debug-over-HTTP and syslog logging, and uses browser localStorage keys to avoid re-exploiting the same device.

Targeting and attribution

iVerify's P7 writeup describes the implant on "one of our customers' devices" and names no victim, sector, or threat actor; it frames P7 as a modified fork of existing DarkSword code whose authors "had invested real effort." Treat any group attribution as unestablished. The exploit-chain module names reference iOS 18.4/18.6 and a hardcoded iPhone OS 18_5 user-agent.

The Hacker News, aggregating the research, ties the broader DarkSword chains to two iOS bugs Apple patched in 2025 — a WebKit sandbox escape (CVE-2025-24201, fixed in iOS 18.3.2) and a Core Audio memory-corruption flaw (CVE-2025-31200, fixed in iOS 18.4.1). iVerify's P7 post itself names no CVE.

Detection artifacts

iVerify published IOCs. Among the on-device file artifacts the implant leaves (pull the authoritative full set — network IOCs and per-component SHA-256 hashes — from the report):

/private/var/tmp/keychain_c2_dump.json
/private/var/tmp/keychain_c2_dump.json.tmp
/private/var/tmp/keychain_c2_dump.done
/private/var/tmp/p7_debug.log
/private/var/tmp/c2_wallet_debug.log
/var/mobile/Library/Caches/ios_disk_scan.txt

The implant also writes browser localStorage keys, including __ds_inflight_worker, __ds_skip_workers, and _x_pe_done.

Action checklist

  1. If you issue iPhones to people plausibly worth a targeted operation — execs, crypto holders, journalists, diplomats — update to the latest iOS now. The known DarkSword chains rely on 2025-era bugs Apple has already fixed.
  2. Pull the full IOC set from iVerify's report and sweep device backups and sysdiagnose output for the file artifacts above and the published C2 domains.
  3. For anyone running the imToken wallet on a possibly-exposed device, rotate wallet credentials and move funds on the assumption that Keychain and wallet data were taken.
  4. Enable Lockdown Mode on high-risk devices; it blunts the WebKit and media-parsing paths these kits favor.

Context

Mercenary-grade iOS exploitation keeps surfacing through endpoint telemetry rather than Apple's own research: last month Apple patched an actively-exploited CoreGraphics zero-day we covered, reported by Meta rather than Apple. P7's twist is financial — bolting imToken wallet theft onto a surveillance implant blurs the line between the commercial-spyware market (see the NSO Group litigation) and plain crypto theft.

Related stories