New DarkSword iPhone spyware variant P7 steals keychain and crypto-wallet data in near real time
Security firm iVerify, according to its report, found a new variant of the DarkSword iPhone exploit chain, named P7 DarkSword after a code prefix, during an August 2026 investigation of an infection on an employee's iPhone at a financial institution. The variant can extract Keychain data and crypto-wallet data on the device and maintain two-way communication with attacker servers, checking in every 15 seconds by default. iVerify said P7 is distributed through malicious ads in watering-hole attacks rather than individually targeted delivery.
Bottom line — iVerify says P7 is harder to detect than earlier variants, so previous indicators of compromise no longer apply and iOS 18.7.7 or later is the relevant patch baseline.
Go deeper 7
-
iVerify said P7 expands compatibility to iOS 18.7, up from iOS 18.6 in the earlier variant it tracked, and that Google had already observed DarkSword deployments supporting iOS 18.7.
-
According to 9to5Mac, iVerify said P7 reduces its on-device footprint, uses browser storage to avoid re-exploiting the same device, and no longer copies the entire Keychain database off the phone.
-
The Hacker News, citing Google's Threat Intelligence Group, reported that DarkSword was linked to UNC6353, which it described as a suspected Russian espionage group targeting Ukrainian users.
-
Digital Trends reported that iVerify said some DarkSword knockoffs had been tweaked with AI help, but P7 showed signs of real developer skill and sustained work.
-
Apple's own guidance, reported by 9to5Mac, was to extend iOS 18.7.7 availability to devices able to run iOS 26, so users who had not moved to iOS 26 could still receive DarkSword protections.
-
iVerify told 9to5Mac it could not say which iOS version the infected device in August was running; the protective update and the P7 detection are reported by the sources as separate facts.
-
The darksword.org technical brief, a secondary source, described the chain as six CVEs and said the exploit operates in memory with low artifacts, a claim it attributes to Google's threat intelligence analysis.