iVerify uncovers new DarkSword spyware variant targeting unpatched iPhones
iVerify has detailed P7 DarkSword, a new variant of the malware tied to the DarkSword iPhone exploit chain. It extends support to iOS 18.7, steals Keychain and crypto-wallet data on-device, and checks in with attackers' command-and-control servers every 15 seconds.
- P7 DarkSword supports iOS 18.7, up from iOS 18.6 in the earlier variant
- The malware extracts Keychain and crypto-wallet data directly on the iPhone
- It contacts the C2 server every 15 seconds, with a remotely adjustable interval
- It spreads via malicious ads in watering-hole attacks
Read next
Security