Loading prices…
🩸BEARISH

P7 DarkSword Targets iPhone Crypto Wallets Every 15 Seconds

The spyware can search for wallet apps, extract credentials and control infected phones remotely, but researchers found no evidence of completed crypto theft or a bypass of current iOS fixes.

iVerify disclosed P7 DarkSword on Oct. 8 after investigating an infection detected in August. The iPhone spyware includes commands that scan for installed cryptocurrency wallets, extract data linked to imToken, and collect passwords, photos, Apple Notes databases and other files. It contacts an attacker-controlled server every 15 seconds by default for new instructions.

Why it matters

P7's wallet_scan function identifies wallet applications on a compromised device, while wallet_extract targets files associated with imToken, a multichain cryptocurrency wallet. The spyware also processes Apple's Keychain credentials into a JSON file on the device before transmitting it, potentially giving operators more immediately usable account information.

The threat extends beyond wallet apps. Recovery phrases or financial credentials stored in Notes, photos or other application files could also be exposed. Finding wallet files does not automatically give an attacker control of private keys, however. Unauthorized transactions would depend on what data is retrieved and whether it is sufficient to authorize transfers.

Market impact

P7 represents an evolution of DarkSword malware deployed after a device has already been compromised, not evidence of a new iOS vulnerability. Google previously linked the framework to campaigns targeting users in Saudi Arabia, Turkey, Malaysia and Ukraine, including activity by commercial surveillance vendors and suspected state-backed attackers.

Apple has addressed the vulnerabilities associated with the documented exploitation chain, with protections expanded through iOS 18.7.7 on March 24, 2026, and to additional devices on April 1. iVerify did not identify which patched versions, if any, remain vulnerable. Apple recommends the latest compatible software and automatic updates, while Lockdown Mode is an additional option when updating is not possible. No completed cryptocurrency theft, affected-user count or financial loss was disclosed.

Related tokens
$BTC

Frequently asked questions

  1. What can P7 DarkSword collect from a compromised iPhone?

    P7 can identify wallet apps, extract imToken-related files, process Apple Keychain credentials, and collect Notes databases, photos and selected application files.

  2. How often does P7 DarkSword contact its operators?

    The spyware contacts an attacker-controlled server every 15 seconds by default. Operators can adjust the interval and request searches or additional collection activities.

  3. Does finding a wallet file give attackers control of the funds?

    No. Wallet files or an installed application do not automatically expose private keys or authorize transfers. Control depends on what information the spyware retrieves.

  4. Is P7 DarkSword evidence of a new iPhone vulnerability?

    No. The investigation describes spyware deployed after a successful compromise. It does not establish that P7 bypasses the latest iOS security updates.

  5. How can iPhone users reduce the risk from DarkSword?

    Users should install the latest compatible iOS version and enable automatic updates. Apple and Google also recommend Lockdown Mode when updating is not possible.

Source attribution
Aggregated from CryptoSlate · Verified · Last refreshed 1h ago
Open original →