techjacksolutions.com • 1h
P7 DarkSword iOS Exploit Kit: Bidirectional C2 and Crypto-Wallet Targeting
The P7 DarkSword iOS exploit kit, discovered in August 2026, is a memory-resident malware-as-a-service that leverages dyld_insert_library for in‑memory payload execution, bypassing iOS code‑signing, and persists via a masqueraded launchd plist (com.apple.securityd.plist). It establishes bidirectional C2 over TLS 1.3/WebSocket, uses private Security.framework APIs to dump Keychain credentials, and scans for MetaMask, Trust Wallet, and Coinbase Wallet to steal seed phrases and private keys, encrypting loot with AES‑256‑GCM for exfiltration to /api/v1/collect.