Full Report
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday. The name
Analysis Summary
# Tool/Technique: P7 DarkSword
## Overview
P7 DarkSword is a sophisticated variant of the DarkSword iOS exploit kit. It is a commercial-grade mobile surveillance tool designed to compromise iPhones by chaining multiple vulnerabilities to escape the browser sandbox and gain kernel-level privileges. This specific variant represents an evolution focused on a reduced device footprint, enhanced data theft (specifically targeting cryptocurrency and keychains), and robust two-way Command and Control (C2) communication.
## Technical Details
- **Type:** Malware variant / Exploit Kit
- **Platform:** iOS (Specifically versions 18.4 through 18.7; recent attempts seen targeting 26.x)
- **Capabilities:** Sandbox escape, privilege escalation, credential theft, two-way C2 communication, and remote command execution.
- **First Seen:** Original DarkSword detected November 2025; P7 variant disclosed October 2026.
## MITRE ATT&CK Mapping
- **TA0037 - Mobilie: Command and Control**
- T1584.005 - Command and Control: Remote Access Software
- T1476 - Remote Service Session Hijacking
- **TA0030 - Mobile: Credential Access**
- T1409 - Access Sensitive Data in Device Keychain
- **TA0029 - Mobile: Discovery**
- T1418 - Software Discovery
- T1420 - File and Directory Discovery
- **TA0032 - Mobile: Collection**
- T1430 - Location Tracking
- T1533 - Data from Local System (Photos, Notes, Wallets)
- **TA0004 - Privilege Escalation**
- T1404 - Exploitation for Privilege Escalation
## Functionality
### Core Capabilities
- **Browser Sandbox Escape:** Utilizes a chain of vulnerabilities to move beyond the initial browser entry point.
- **Privilege Escalation:** Gains kernel-level access to the iOS operating system.
- **Payload Injection:** Injects the main malicious implant into the `SpringBoard` process (the iOS home screen/app launcher).
- **Two-way C2:** Polls the attacker’s infrastructure every 15 seconds for new tasks and sends "heartbeat" status messages.
- **Directory & File Enumeration:** Uses commands like `ls`, `dir`, and `disk_scan` to map the device filesystem.
### Advanced Features
- **On-Device Data Processing:** Unlike earlier versions that exfiltrated raw databases, P7 extracts Keychain data into JSON format locally before transmission to reduce traffic noise.
- **Crypto-Wallet Theft:** Features specialized modules (`wallet_scan`, `wallet_extract`) specifically targeting the imToken wallet and other crypto-applications.
- **Stealth Enhancements:** Removes debug logging (HTTP and syslog) and uses browser `localStorage` to track state and prevent redundant re-exploitation attempts.
- **LLM-Assisted Development:** Evidence suggests threat actors are using Large Language Models to attempt porting the exploit to newer iOS versions.
- **Arbitrary Execution:** Ability to execute remote OS commands and arbitrary JavaScript within the implant runtime.
## Indicators of Compromise
- **File Names:** Uses `p7_` variable prefixes within the code structure.
- **Network Indicators:**
- Communication with C2 via HTTP/HTTPS (specific domains not listed in the text; ensure monitoring for high-frequency 15-second heartbeats).
- C2 infrastructure associated with **PARS Defense** and **Star Blizzard**.
- **Behavioral Indicators:**
- `SpringBoard` process making unusual outbound network connections.
- Presence of high-frequency polling (every 15 seconds) to external infrastructure.
- Unusual access to `/var/mobile/Media/DCIM` and Apple Notes/Keychain by unauthorized processes.
## Associated Threat Actors
- **PARS Defense:** A Turkish commercial surveillance vendor.
- **Star Blizzard (COLDRIVER):** A Russia-aligned threat actor.
- **Unnamed Chinese-speaking actors:** Observed using the kit with Apple ID decoy pages.
## Detection Methods
- **Behavioral Detection:** Monitor for the 15-second beaconing interval and unusual SpringBoard process activity. Check for unauthorized access to sensitive directories like `/var/mobile/Media/DCIM`.
- **Heuristic Scanning:** Look for the use of browser `localStorage` entries used to flag successful exploitation states.
- **Network Monitoring:** Identify two-way communication patterns where the device sends a heartbeat and receives structured commands (JSON/JavaScript) in response.
## Mitigation Strategies
- **Operating System Updates:** Keep iOS devices updated to the latest versions to patch the vulnerabilities (18.4–18.7) exploited by this kit.
- **Mobile Device Management (MDM):** Implement MDM solutions to detect jailbreak-like activities or unauthorized process injections.
- **Security Awareness:** Train users to avoid clicking links in unsolicited messages (e.g., fake Snapchat or invitation lures).
- **Hardening:** Use Lockdown Mode on iOS for high-risk individuals to reduce the browser attack surface.
## Related Tools/Techniques
- **DarkSword (Base):** The original version of the exploit kit.
- **Coruna:** Another iOS exploit kit frequently observed alongside DarkSword.
- **Commercial Surveillance Software:** Similar in nature to Pegasus or Predator.