Breaking
Cyber CrimeDeveloping Story

DarkSword Kit Grows a Wallet-Stealing Arm

A new P7 DarkSword variant trims its on-device footprint while adding keychain theft, crypto-wallet extraction, and two-way command control.

··1 hour ago·8 min read
black android smartphone turned on displaying icons
Photo by Árpád Czapp on Unsplash

A leaked iOS exploit kit that has already been passed between surveillance vendors and state-aligned crews is now being rebuilt for a different job: emptying cryptocurrency wallets. iVerify reported this week that it has analyzed a previously unseen build of DarkSword, which it calls P7 DarkSword, and found the tooling reworked to steal keychain and wallet data while hiding itself more effectively on the phone.

The name is not arbitrary. According to iVerify, "P7" comes from the threat actor's habit of prefixing its edits to the original DarkSword code with the variable string "p7_". The report was published on Thursday, with iVerify attributing its findings to its own analysis of the variant.

A Toolkit That Was Never Meant to Leak

DarkSword was first publicly documented in March by Google Threat Intelligence Group, iVerify, and Lookout. At the time, the kit's purpose was described as chaining multiple iOS vulnerabilities together to escape the browser sandbox, escalate to kernel privileges, and inject a payload into SpringBoard — the iOS process responsible for launching apps and drawing the home screen.

That chain is assessed to be a commercial product. How it ended up outside its original buyer is a detail the reporting does not resolve, but the working theory is that it reached a second-hand market and was picked up by financially motivated operators and other threat actors from late 2025 onward. The kit was detected in the wild in November 2025 and described as targeting iPhones running iOS versions between iOS 18.4 and 18.7.

Its operator base is unusually varied for a single tool. iVerify's earlier work tied DarkSword use to attacks in Saudi Arabia, Turkey, Malaysia, and Ukraine, run by multiple threat actors — among them PARS Defense, a Turkish commercial surveillance vendor that used a fake Snapchat-themed website, and the Russia-aligned group known as Star Blizzard, also tracked as COLDRIVER, which relied on fake invitation lures.

Why This Variant Is Harder to Spot

The P7 build is not a rewrite so much as a hardening pass. iVerify said the variant cuts its on-device footprint, and the changes it lists are aimed squarely at the traces an incident responder would look for first. Debug logging over HTTP requests is gone. So is syslog output. To keep a victim from being re-exploited — or perhaps to keep the device from being claimed by another operator — the implant uses browser localStorage as a marker.

Theft mechanics changed too. Earlier DarkSword variants copied the keychain database off the device and exfiltrated it for processing on the attacker's own infrastructure. P7 inverts that: it extracts keychain data into JSON on the phone itself and then exfiltrates the result.

Where the implant lives has not changed. As iVerify put it: "The implant is injected into the SpringBoard process, which handles all communication with the attacker's infrastructure."

Heartbeats, Polling, and a Command Menu

P7 DarkSword polls its command-and-control server every 15 seconds. Each contact sends a heartbeat message alongside a list of applications installed on the device, and the implant also transmits iCloud Keychain information plus data pulled from apps including Apple Notes, Photos, and cryptocurrency wallets.

The server's reply is where the operator's intent shows. iVerify laid out the command set the implant will execute when the periodic tasking poll returns instructions:

  • execute_command — run operating system commands such as ls, dir, cat, mkdir, rm, echo, ps, memdump, ipconfig, netstat, and whoami
  • ls — list directory contents
  • download — read a file from the device and upload it to the C2 server
  • photos — upload photo files from "/var/mobile/Media/DCIM"
  • apps — enumerate app containers and extract bundle IDs
  • exec — execute arbitrary JavaScript directly inside the implant runtime
  • file_upload — recursively scan one or more paths and upload matching files
  • basic_info — send device metadata to the C2 server
  • disk_scan — recursively scan the filesystem starting from "/,", record metadata for files, directories, and symlinks, and upload the information as a report
  • ios_app_data — find app sandbox and app-group containers for requested bundle IDs and upload selected app files
  • wallet_scan — scan for installed wallet apps
  • wallet_extract — extract wallet-related data for the imToken wallet app
  • memo_scan — upload Apple Notes databases
  • photo_scan — upload photos from Apple Photos
  • sleep — modify the beacon polling interval
  • exit — halt the beacon loop and stop the implant

Two of those entries — wallet_scan and wallet_extract — are the clearest sign of what iVerify describes as an added emphasis on crypto-wallet theft. The rest amount to full remote control of the handset, from arbitrary JavaScript execution inside the implant runtime to filesystem-wide metadata collection.

Leak Fuels Sloppy, LLM-Assisted Rebuilds

The P7 build did not appear in a vacuum. iVerify said that as recently as last month it observed "multiple unsuccessful, likely LLM-assisted attempts to update the framework to support iOS 26.x" — efforts the company tied to the exploit kit's leak shortly after its public disclosure.

Those attempts did not succeed, but they indicate what the copycat pool is chasing. The company described the variants it has seen as focused on stability, stealth, and quality of stolen data. P7 fits that pattern: noisier logging removed, a re-exploitation guard added, and extraction moved closer to the device so the loot arrives in a more usable form.

Open Directories and an Agent-Reseller Model

Alongside the variant analysis, Censys reported open directories on five hosts carrying components tied to DarkSword and to Coruna — a separate iOS exploit kit that has been weaponized against iPhone models running iOS versions between 13.0 and 17.2.1.

The two kits are not rivals. Censys described them as parts of one supply chain: "Coruna is the companion payload kit the same ecosystem distributes," the company said. "Its stages run inside the victim's browser session after DarkSword's exploit stages land, and its wallet-harvesting modules steal crypto recovery phrases, balances, and keystore data from iOS apps. Operators run DarkSword and Coruna together against their own C2 infrastructure."

The five exposed hosts, as listed by Censys:

  • 43.134.165[.]205 — serves DS-Fusion v1.0 (also called DarkSword Fusion), a combined package bundling DarkSword and Coruna
  • 166.88.95[.]90 — a C2 server for the implant, which logged two real Chinese iOS devices (183.154.173[.]30 and 182.239.114[.]223) polling a beacon page every three seconds for several hours on September 6, 2026
  • 23.148.212[.]237 — an analysis workspace showing the operator developing exploit chains for iOS 26, such as for CVE-2026-31001, which neither DarkSword nor Coruna covers
  • 47.102.192[.]23 — a staging host for the Coruna kit
  • 156.239.230[.]120 — exposes the entire C2 platform and was observed polling a device on September 15, 2026

Censys suspects the open-directory cluster and the 156.239.230[.]120 platform are run by a Chinese-speaking threat actor pursuing cryptocurrency wallet theft, though it states plainly that exactly who is behind the operation is unknown.

"The platform runs a Chinese-speaking exploitation-as-a-service operation. The admin panel exposes an agent/reseller model, and a copy of the production server recovered 11 victim recovery phrases, 179 device loot directories, and a 75-account control-plane roster."

— Aidan Holland, Censys researcher

Censys also reported detecting a separate China-based operator running the same kit in the wild against its own C2 server at "66ds[.]lol," and targeting a cryptocurrency wallet app, BitKeep, that did not appear in the open-directory set. That operator, the company said, sits on Tencent and Shenyang hosting and is tied to the operation through a unique self-signed certificate authority.

Two Undocumented Flaws in the Registry

An analysis of the production server's exploit registry turned up two CVE identifiers that had not previously been documented. Both are now attributed to the DarkSword exploit kit:

  • CVE-2025-24201 — an out-of-bounds write in the WebKit engine that could let an attacker break out of the Web Content sandbox; fixed in iOS 18.3.2 and iPadOS 18.3.2
  • CVE-2025-31200 — a memory corruption vulnerability in the Core Audio framework that allows code execution when processing an audio stream in a maliciously crafted media file; fixed in iOS 18.4.1 and iPadOS 18.4.1

Both carry patch versions, which places the exploitation window squarely on devices that have not been updated. The registry finding also shows how much of the kit's capability was never visible in earlier public reporting.

What the Proliferation Means for Defenders

Two things stand out for anyone defending iPhones. The first is that patch level is now the dividing line. The two newly documented flaws were fixed in iOS 18.3.2 and iOS 18.4.1 respectively, while DarkSword's documented target range runs from iOS 18.4 to 18.7 — a span that overlaps with unpatched builds. Devices left on older releases sit inside territory the kit is built to cover.

The second is the shift in what gets taken. Moving keychain extraction into JSON on the phone, and adding dedicated wallet_scan and wallet_extract commands, suggests the operators behind this ecosystem are optimizing for the fastest path to liquid value rather than for long-term espionage access. A stolen recovery phrase cannot be rotated the way a password can, which raises the stakes of a single successful infection well beyond the usual breach calculus.

The broader concern is that DarkSword and Coruna are no longer confined to the well-resourced buyers who might once have commissioned them. Open directories, reseller admin panels, and a leaked framework being patched up in public with likely LLM assistance all point to a toolchain that has slipped into a commodity market. Censys' count of 11 victim recovery phrases and 179 device loot directories on a single recovered production server is a snapshot, not a total — and it is enough to suggest the operations are running, not just being staged.

For managed fleets, that argues for treating iOS patch compliance as a crypto-security control, not just a hygiene item, and for watching for the kind of periodic beacon traffic that P7's 15-second poll would generate on a compromised handset. For individual users, the practical inference from the CVE list is narrow and unglamorous: the fixes exist, and the exposure is concentrated among devices that skipped them.

#darksword#ios exploit kit#crypto wallet theft#coruna#mobile malware#cve-2025-24201

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories