P7 DarkSword iOS Exploit Kit: Bidirectional C2 and Crypto-Wallet Targeting
The P7 DarkSword iOS exploit kit, discovered in August 2026, is a memory-resident malware-as-a-service that leverages dyld_insert_library for in‑memory payload execution, bypassing iOS code‑signing, and persists via a masqueraded launchd plist (com.apple.securityd.plist). It establishes bidirectional C2 over TLS 1.3/WebSocket, uses private Security.framework APIs to dump Keychain credentials, and scans for MetaMask, Trust Wallet, and Coinbase Wallet to steal seed phrases and private keys, encrypting loot with AES‑256‑GCM for exfiltration to /api/v1/collect.
-
Campaign Overview: Evolution of DarkSword
- Identified by iVerify during an August 2026 infection investigation; marks a tactical upgrade to the DarkSword lineage.
- Targets high‑net‑worth iOS users in North America, Europe, and Southeast Asia via an Exploitation‑as‑a‑Service (EaaS) model.
- Affiliates obtain pre‑built payloads, C2 panels, and automated update services from a login‑protected portal.
-
Technical Execution: Stealth & Persistence
- Uses
dyld_insert_libraryto load malicious Mach‑O (<200 KB) into legitimate processes, avoiding on‑disk traces. - Persists via a malicious launchd plist named
com.apple.securityd.plistplaced in/Library/LaunchDaemons. - Employs anti‑analysis checks:
ptracedenial, sandbox detection viasysctl kern.jailroot, and device‑model verification to thwart emulators.
- Uses
-
Command & Control: Bidirectional Communication
- Communicates over encrypted TLS 1.3 HTTPS with a WebSocket fallback, mimicking legitimate traffic to evade network monitoring.
- Sends JSON‑wrapped commands (e.g.,
{"cmd":"get_keychain","token":"…"}) for real‑time tasking and data exfiltration. - C2 endpoints typically hosted on bullet‑proof domains; exfiltration URL path
/api/v1/collectreceives AES‑256‑GCM blobs.
-
Targeted Modules: Keychain & Crypto‑Wallet Theft
- Calls private
Security.frameworkAPIs (SecItemCopyMatching,SecKeychainItemCopyContent) to extract passwords, VPN tokens, and MDM certificates. - Scans for wallet apps using URL‑scheme handlers (
metamask://,trustwallet://,coinbase://) and file‑system probes for MetaMask, Trust Wallet, Coinbase Wallet, Binance Chain Wallet. - Packages stolen seeds, private keys, and Keychain items into AES‑256‑GCM encrypted blobs before upload.
- Calls private
-
Impact Assessment: Financial & Enterprise Risk
- First‑month activity resulted in several hundred thousand USD drained from cryptocurrency wallets of infected devices.
- Compromised Keychain entries enable theft of VPN tokens and MDM enrollment certificates, facilitating lateral movement into corporate networks.
- The EaaS distribution model lowers the skill barrier, increasing the frequency of targeted iOS espionage and financial crime campaigns.
Related posts
- Wiu
- Columbiabasin
- cyberinsider.com — New DarkSword iPhone spyware variant adds stealth and remote control
- The Hacker News — P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
- www.idropnews.com — DarkSword Gets an Upgrade: Why Updating Your iPhone Still Matters
- Vietnamnet
- Hacklido
- Iverify
- Aviatrix