Mobile security firm iVerify has published details of P7 DarkSword, a previously unseen variant of the DarkSword iOS exploit kit, which it found in August 2026 while investigating an infected iPhone belonging to a customer. According to iVerify’s report, the variant “reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure.”

The report says the implant sits inside the SpringBoard process and polls its command server every 15 seconds. It can exfiltrate installed-app lists, Apple Notes databases and photos, and it has handlers that scan for wallet apps and extract data from the imToken wallet. Earlier DarkSword versions copied the keychain database off the phone for processing elsewhere. P7 extracts keychain data into JSON on the device first. The exploit components named in the report cover iOS 18.4 through 18.7. iVerify publishes network indicators, file hashes and on-device filesystem artifacts so responders can hunt for it.

Why it matters: iVerify contrasts P7 with the many AI-assisted variants it sees, saying its authors “invested real effort” and that the changes “demonstrated competence.” The kit is circulating among operators who modify it, so detection written against the original will miss variants.

Our read: a keychain holds saved passwords and tokens, so a confirmed infection means rotating every credential stored on the phone, not only wiping the device. Security teams that exempt personal or executive phones from mobile threat monitoring should revisit that, and keep iOS current, including fixes like Apple’s recent patch for a graphics flaw used against targets. We also covered a fake crypto wallet hiding Mac malware in iCloud.

Source: iVerify, P7 DarkSword variant threat research