Image: blogger.googleusercontent.com · rights & removal
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Reporting by The Hacker NewsRead the original at thehackernews.com
Executive Summary
The P7 DarkSword exploit kit represents an evolution of a commercial iOS vulnerability chain now utilized by various financially motivated actors and state-aligned entities. By chaining multiple vulnerabilities to escape browser sandboxes and escalate privileges, the toolkit injects payloads into the SpringBoard process to steal keychain data, cryptocurrency wallet information, and personal files. The kit has been deployed in campaigns targeting Saudi Arabia, Turkey, Malaysia, and Ukraine, often utilizing fake websites or invitation lures.
Recent developments indicate the proliferation of the kit through second-hand markets and public leaks, leading to "AI-assisted" attempts by less sophisticated actors to update the framework for newer iOS versions. There is evidence of a Chinese-speaking "exploitation-as-a-service" operation offering the kit via a reseller model. While some deployments are highly sophisticated, others are non-functional versions sourced from GitHub. The infrastructure relies on diverse delivery methods, including the hijacking of expired e-commerce domains and the use of decoy sign-in pages to facilitate theft.
Facts Only
P7 DarkSword is a variant of the DarkSword iOS exploit kit.
DarkSword targets iOS versions 18.4 through 18.7.
The kit was first detected in the wild in November 2025.
P7 DarkSword adds on-device keychain theft, crypto-wallet theft, and two-way C2 communication.
Attacks have targeted Saudi Arabia, Turkey, Malaysia, and Ukraine.
Identified actors include PARS Defense, Star Blizzard, and unknown Chinese-speaking threat actors.
The exploit chain utilizes CVE-2025-24201 (WebKit) and CVE-2025-31200 (Core Audio).
The kit injects payloads into the iOS SpringBoard process.
P7 DarkSword polls for commands every 15 seconds.
The domain ecomtrack[.]io was re-registered on September 15, 2026, to distribute the exploit.
Coruna is a companion payload kit targeting iOS versions 13.0 to 17.2.1.
Five hosts were identified serving DarkSword and Coruna components, including 156.239.230[.]120 and 43.134.165[.]205.
Full Take
The strongest version of this narrative is that commercial-grade surveillance tools are rapidly commoditizing, moving from elite state arsenals to a fragmented "exploitation-as-a-service" market where even non-sophisticated actors use LLMs to attempt updates.
This situation reveals a critical pattern: the "democratization" of high-end cyber-weapons. We are seeing a transition from targeted espionage to opportunistic financial crime. The mention of "AI slop" and unsuccessful LLM-assisted updates suggests a new era of "script kiddie" behavior where the barrier to entry is lowered by AI, even if the success rate remains low for those without deep kernel knowledge.
The root cause is the intersection of the private surveillance market and the dark web. When commercial kits leak or are resold, they create a permanent "long tail" of risk for older OS versions. The assumption here is that software updates are the primary defense, but the existence of a second-hand market for exploits means that "fixed" vulnerabilities are often just shifted to different target demographics.
This erodes the concept of device sovereignty. If a browser visit to a legacy tracking tag can lead to a full kernel compromise, the "sandbox" becomes a psychological comfort rather than a technical guarantee. The cost is borne by the end-user, while the benefit accrues to a shadow economy of resellers and "agents."
Patterns detected: none
Bridge Questions:
1. If LLMs can assist in updating exploit frameworks, how does this change the timeline between a patch release and a new "wild" variant?
2. To what extent does the "exploitation-as-a-service" model incentivize the discovery of new 0-days versus the recycling of old ones?
3. How can users verify the integrity of their device when the implant resides in a core process like SpringBoard?
Counterstrike Scan: A coordinated campaign pushing this narrative would seek to instill a sense of helplessness regarding mobile security to drive users toward a specific "hardened" OS or security product. This content is a technical briefing and does not match that pattern.
From the original · The Hacker News
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. "Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure," iVerify said in a new report published Thursday.Read the full story at thehackernews.com
Sentinel — provisional
No strong signs of machine writing were found in the source article. Provisional estimate, not a finding that a person wrote it.
The text appears to be a synthesis of technical disclosures, relying on multiple named sources to build a detailed forensic picture of an exploit kit's use, suggesting strong human editorial oversight rather than pure AI generation.
This looks only at the wording of the original source article, not at this page's AI-written sections. A small local AI model made this estimate. It has not been checked against known human and machine texts, so treat it as provisional. It cannot show who wrote an article.
