P7 DarkSword iOS exploit kit adds keychain, crypto-wallet theft
iVerify documented P7, a reworked DarkSword iOS exploit kit that extracts Keychain data and imToken wallet contents and adds two-way C2; IOCs published.
iVerify has documented P7 DarkSword, a reworked variant of the DarkSword iOS exploit kit that pulls Keychain data and cryptocurrency-wallet contents off compromised iPhones and adds a two-way command-and-control channel. iVerify's threat-research writeup is the primary source, published October 11; The Hacker News corroborated it with ecosystem detail from Report URI and Censys.
What P7 changes
iVerify says the "P7" label comes from the operator's use of a p7_ variable prefix in modifications to the original DarkSword code. Against earlier builds, P7:
- Converts Keychain contents to JSON on-device before exfiltration, instead of copying the Keychain database off the phone.
- Adds a
wallet_extracthandler that "Extracts wallet-related data for imToken wallet app" and awallet_scanhandler that enumerates installed wallet apps. - Beacons to its C2 every 15 seconds (configurable via a
sleepcommand) and exposes a command dispatcher covering file operations, process listing, Photos, installed-app inventory, Notes scraping, and arbitraryexec/eval. - Drops debug-over-HTTP and syslog logging, and uses browser
localStoragekeys to avoid re-exploiting the same device.
Targeting and attribution
iVerify's P7 writeup describes the implant on "one of our customers' devices" and names no victim, sector, or threat actor; it frames P7 as a modified fork of existing DarkSword code whose authors "had invested real effort." Treat any group attribution as unestablished. The exploit-chain module names reference iOS 18.4/18.6 and a hardcoded iPhone OS 18_5 user-agent.
The Hacker News, aggregating the research, ties the broader DarkSword chains to two iOS bugs Apple patched in 2025 — a WebKit sandbox escape (CVE-2025-24201, fixed in iOS 18.3.2) and a Core Audio memory-corruption flaw (CVE-2025-31200, fixed in iOS 18.4.1). iVerify's P7 post itself names no CVE.
Detection artifacts
iVerify published IOCs. Among the on-device file artifacts the implant leaves (pull the authoritative full set — network IOCs and per-component SHA-256 hashes — from the report):
/private/var/tmp/keychain_c2_dump.json
/private/var/tmp/keychain_c2_dump.json.tmp
/private/var/tmp/keychain_c2_dump.done
/private/var/tmp/p7_debug.log
/private/var/tmp/c2_wallet_debug.log
/var/mobile/Library/Caches/ios_disk_scan.txt
The implant also writes browser localStorage keys, including __ds_inflight_worker, __ds_skip_workers, and _x_pe_done.
Action checklist
- If you issue iPhones to people plausibly worth a targeted operation — execs, crypto holders, journalists, diplomats — update to the latest iOS now. The known DarkSword chains rely on 2025-era bugs Apple has already fixed.
- Pull the full IOC set from iVerify's report and sweep device backups and sysdiagnose output for the file artifacts above and the published C2 domains.
- For anyone running the imToken wallet on a possibly-exposed device, rotate wallet credentials and move funds on the assumption that Keychain and wallet data were taken.
- Enable Lockdown Mode on high-risk devices; it blunts the WebKit and media-parsing paths these kits favor.
Context
Mercenary-grade iOS exploitation keeps surfacing through endpoint telemetry rather than Apple's own research: last month Apple patched an actively-exploited CoreGraphics zero-day we covered, reported by Meta rather than Apple. P7's twist is financial — bolting imToken wallet theft onto a surveillance implant blurs the line between the commercial-spyware market (see the NSO Group litigation) and plain crypto theft.