Tech & Science
A new malware variant, P7 DarkSword, has been identified by iVerify, expanding data theft capabilities and evading previous detection methods on iOS devices.

Security firm iVerify has published findings on a novel iteration of the DarkSword spyware, designated P7 DarkSword. This variant was detected during an investigation into a compromised iPhone belonging to a financial sector employee two months ago. The discovery highlights ongoing threats to devices running specific, unpatched versions of iOS.
Context for this development lies in earlier disclosures by Google and iVerify regarding sophisticated hacking tools named Coruna and DarkSword. These exploits chained multiple iOS vulnerabilities to compromise devices operating on outdated system software. While Coruna targeted iOS 13 through 17.2.1, DarkSword affected iPhones running iOS 18.4 through 18.7.
Apple responded to these threats by issuing updates for older versions, including iOS 15.8.7, 16.7.15, and 18.7.7. In an unusual move, Apple made iOS 18.7.7 available even to devices capable of installing iOS 26, ensuring protection for users who chose not to upgrade to the latest major release. At that time, Google noted DarkSword usage by commercial surveillance vendors and suspected state-sponsored actors, with attacks observed in Saudi Arabia, Turkey, Malaysia, and Ukraine.
The newly identified P7 variant expands compatibility to iOS 18.7, an improvement over the iOS 18.6 support seen in previously tracked iterations. According to details shared with 9to5Mac, the threat actor distributes P7 via malicious advertisements within watering-hole attacks. This method means victims are not necessarily individually targeted; rather, they may be caught in broader campaigns simply by visiting compromised or malicious web content.
In its report, iVerify explained that the "P7" designation derives from the attacker’s use of the p7_ variable prefix in code modifications. Compared to standard variants, P7 reduces its on-device footprint and introduces two-way command-and-control (C2) communication. It also adds capabilities for stealing keychain and crypto-wallet data directly on the device.
The variant improves upon predecessors in three areas: stealth, stability, and functionality. It minimizes logging and process injections, utilizing browser storage to avoid repeated exploitation of the same device. iVerify stated that these changes reflect substantial operator effort rather than simple AI-assisted tweaks. Consequently, previous indicators of compromise (IOCs) are no longer valid as P7 is more effective at hiding its presence and cleaning up its behavior.
A significant enhancement in P7 is its ability to extract Keychain data directly on the iPhone before transmission, rather than copying the entire database for external processing. The malware also targets crypto-wallet information. The introduction of advanced two-way C2 communication grants attackers considerable control over infected devices.
According to iVerify, P7 can receive commands to retrieve arbitrary files, upload photos, inventory installed applications, access Apple Notes databases, collect data from individual app containers, and scan the device’s filesystem. By default, the spyware checks in with the attacker’s server every 15 seconds for new instructions, though this interval can be altered remotely.
It is important to note that P7 represents a new version of malware deployed after a successful DarkSword compromise, not a new iOS vulnerability itself. iVerify did not specify which iOS version was running on the device where the August 2026 infection was discovered.



