Six months after the exposure of the DarkSword exploit chain, an improved version has surfaced. It leaves fewer traces, analyzes passwords directly on the device, and accepts commands remotely. However, it only poses a threat to iPhones that haven't received an update in months.
DarkSword is a chain of six vulnerabilities that enters Safari via a specially crafted website, leaves the sandbox, and works its way into the system kernel. The Google Threat Intelligence Group described it in a detailed report in March, and a few days later the code for the chain was publicly available on GitHub. Now, the mobile security firm iVerify has documented a previously unknown variant in a report dated October 8th. It is named P7 after an abbreviation the attackers used to mark their own additions to the code.
Key Facts at a Glance
- In August, iVerify investigated a DarkSword infection at one of its own customers, which turned out to be a new variant called P7.
- P7 builds on the known exploit chain and does not use any new iOS vulnerability.
- This version analyzes the keychain directly on the iPhone, searches for crypto wallets, and queries for new commands every 15 seconds.
- The components target iOS 18.4 to 18.7. Devices with the current iOS 27 or a patched iOS 18 are protected.
What the iPhone version does
After a successful attack, P7 embeds itself in the process that controls the home screen and connects to an attacker's server. From there, the implant receives commands. According to iVerify, it can extract photos, notes, the list of installed apps, and any files, as well as scan the file system.
In addition, there are two functions with a clear focus on money: P7 specifically searches for installed crypto wallets and includes a dedicated routine for the imToken wallet app. The keychain containing stored access data is read from the device and sent as a ready-to-use file.
By default, the device queries for new commands every 15 seconds. Attackers can change this interval remotely and execute arbitrary code on the device.
What has changed compared to DarkSword
iVerify describes three areas in which P7 improves upon previous versions: camouflage, stability, and functionality.
| Area | Previous DarkSword versions | P7 |
|---|---|---|
| Traces on the device | Logging via HTTP and system log | removed, less interference in other processes |
| Multiple infections | – | Marking in browser memory prevents repeated attacks on the same device. |
| Keychain | Complete database copied and extracted | The evaluation is performed on the device; only the result is sent. |
| Steering | – | Commands in both directions via the attackers' server |
Fewer traces make detection on an affected device more difficult. iVerify also explicitly distinguishes P7 from the many AI-powered modifications the company has observed: The operators understood the code and specifically modified it, instead of merely superficially adapting it.
Which iPhones are vulnerable?
The files in this variant are tailored to iOS 18.4 to 18.7, the same range that Google identified for the original chain. According to Google's list, Apple closed the six exploited vulnerabilities with iOS 18.7.3, as well as iOS 26.2 and 26.3. For even older systems, iOS 16.7.15 and iOS 15.8.7 followed in the spring.
In early April, Apple also rolled out iOS 18.7.7 to devices that could potentially upgrade to iOS 26. According to Apple's security advisory for iOS 18.7.7, this should also provide protection against such attacks via websites for users with automatic updates enabled.
The report does not disclose who was affected; it is only known that it was an iVerify customer. iVerify also does not specify the iOS version of the infected device.
Why unpatched iPhones are the real target
For users of a current iPhone with iOS 27, P7 is no cause for concern. Nevertheless, I consider this variant a serious development because it demonstrates how a publicly exposed spyware tool is being further refined. With its wallet search and keychain analysis capabilities, P7's functions clearly target money as well – not just information. This variant thus joins a series of attacks on iPhones that have dominated the topic of cybersecurity this year.
The target audience is determined by the technology: iPhones that haven't been updated. This primarily affects the iPhone XS, XS Max, and XR, which will no longer receive iOS 26 and remain on iOS 18, but also devices where automatic updates are disabled. If you have such an iPhone in your family, it's worth checking under Settings > General > Software Update. Apple provides these older devices with their own security updates, even if they no longer receive a new iOS generation.
Anyone unable to update their device, or who faces an increased risk as a journalist, activist, or executive, can additionally activate blocking mode on their iPhone. Google explicitly recommended this in March for cases where an update is not possible. According to Google, a commercial surveillance provider also deployed DarkSword – the same business model as Pegasus and other commercial spyware on the iPhone.
Does anyone in your circle of friends or family still have an iPhone stuck on iOS 18 – and do you know when it last received an update? Tell us in the comments how you secure older devices within your family.





