Unpatched iPhones Are Being Targeted by P7 DarkSword Spyware Built for 'Crypto-Wallet Theft'
Researchers found P7 DarkSword spyware targeting unpatched Apple iPhones, with capabilities including Keychain and crypto-wallet data theft

A new P7 DarkSword spyware variant is targeting unpatched Apple iPhones, researchers said on Thursday, 8 October, after finding an infection on a financial institution employee's device in August 2026. The malware can extract Keychain data, search for crypto-wallet information and receive commands to steal files, photos and notes.
The discovery was reported by mobile security company iVerify. Its researchers said P7 DarkSword is a previously unseen version of the malware associated with a wider iOS exploit chain. The company has not said which iOS version was installed on the infected device.
DarkSword Expands Across Apple iPhone Devices
For context, Google Threat Intelligence Group identified DarkSword in March 2026 as a full-chain iOS exploit. The tool used six vulnerabilities to compromise devices running iOS 18.4 through iOS 18.7.
Google said commercial surveillance vendors and suspected state-backed actors had used DarkSword in campaigns involving targets in Saudi Arabia, Turkey, Malaysia and Ukraine. It also identified several malware families deployed after a successful compromise.
Apple subsequently released security updates for affected devices. The company said users running updated software were protected from the reported web-based attacks. It also expanded iOS 18.7.7 availability so more older devices could receive protection without upgrading to iOS 26.
That distinction matters. P7 DarkSword is not a newly discovered iOS vulnerability. It is a malware revision deployed after an attacker has successfully used the DarkSword exploit chain against a vulnerable device.
The immediate risk therefore falls on people who have delayed updates, particularly where a malicious advert or compromised website is involved.
P7 DarkSword Adds Crypto-Wallet Theft
iVerify said the operators are distributing P7 through malicious advertising and watering-hole attacks. That means an Apple iPhone user may encounter the threat while visiting compromised web content, rather than being individually selected in advance.
The company described three central changes in P7. It is more discreet, more stable and able to steal more information than earlier versions.
The spyware removes debug logging from HTTP requests and system logs. It also reduces process injections, limiting some of the activity that could expose an infection during forensic analysis. Browser local storage helps it avoid repeatedly exploiting the same device.
The most sensitive change concerns Keychain data. Earlier DarkSword variants copied the Keychain database for processing elsewhere. P7 instead extracts relevant information on the device and prepares it for transmission.
iVerify also found code for crypto-wallet theft. The implant can scan for installed wallet applications and extract wallet-related data. That creates a direct financial risk, although the report does not establish that funds were stolen from the infected device.
The spyware's command-and-control system gives operators considerable flexibility. It can be instructed to retrieve arbitrary files, upload photos, list installed applications, collect data from individual app containers and scan the filesystem.
It can also search Apple Notes databases. For people who store recovery phrases, passwords or financial details in Notes, that capability is especially troubling. A private note can become a useful target without any dramatic warning on the screen.
Apple iPhone Users Told To Update
P7 communicates with its operators through the SpringBoard process, which manages much of the iPhone's interface and system interaction. By default, iVerify said, the implant checks for new instructions every 15 seconds. That interval can be changed remotely.
The company said the revisions appeared to reflect deliberate development by people who understood the underlying code. In other words, this was not simply a rough automated remix of existing spyware. The changes make older indicators of compromise unreliable.
Apple's own guidance remains straightforward. It says users should install the latest available iOS update, while those unable to update should consider enabling Lockdown Mode if their device supports it. Apple also said updated devices were not at risk from the reported attacks.
Google's earlier research found that DarkSword had been patched across successive iOS updates, with the remaining fixes included in iOS 26.3. The advice is therefore less glamorous than the spyware itself, but far more useful. Update the phone, avoid suspicious web pages and do not treat a familiar-looking advert as proof that a site is safe.
iVerify's report confirms an active malware-development effort, not a fresh vulnerability affecting every Apple iPhone. The precise number of infections linked to P7 remains unclear, and the company has not publicly identified the threat actor behind the variant.
For users who have kept their devices patched, the immediate danger appears limited. For everyone else, the window for ignoring that update is getting uncomfortably small.
© Copyright IBTimes 2026. All rights reserved.

