Researchers uncover new DarkSword spyware variant affecting unpatched iPhones
AI-summarised brief · reviewed before publication
iVerify released a report detailing P7 DarkSword, a new variant of the DarkSword iPhone spyware first identified earlier this year. The original DarkSword chain exploited multiple iOS flaws in versions 18.4‑18.7, prompting Apple to issue emergency updates for older releases. P7 expands compatibility to iOS 18.7, reduces its on‑device footprint, and adds direct keychain and crypto‑wallet theft, two‑way command‑and‑control, and data‑exfiltration capabilities. Unlike prior versions that relied on targeted attacks, P7 is distributed through malicious ads in watering‑hole campaigns, allowing infection of any user who visits compromised web content. The variant also evades earlier indicators of compromise by minimizing logging and process injections, and it can issue commands every 15 seconds to retrieve files, upload photos, and scan app containers.
💡 Why It Matters
- · By turning a targeted exploit into a mass‑distribution ad‑based threat, P7 dramatically widens the attack surface for high‑value iPhone users, forcing enterprises to reassess mobile security beyond patch management.