Live Prices
Bitcoin

iPhone Spyware P7 DarkSword Targets Mobile Crypto Wallets and Keychain Data

TheCryptoDesk Editorial · 2m read
iPhone Spyware P7 DarkSword Targets Mobile Crypto Wallets and Keychain Data

Cybersecurity firm iVerify disclosed on Oct. 8 that a new iPhone spyware variant, designated P7 DarkSword, is actively scanning compromised devices to extract cryptocurrency wallet data and sensitive credentials every 15 seconds.

Dedicated Commands Target imToken and Keychain

According to iVerify's technical investigation into an infection detected in August, the P7 variant introduces two explicit commands aimed at mobile cryptocurrency users: wallet_scan to search for installed wallet applications and wallet_extract to harvest data from imToken, a popular multi-chain crypto wallet.

Beyond target wallet files, P7 targets Apple's Keychain password management system. Unlike earlier DarkSword variants that copied the entire raw Keychain database to remote servers, P7 formats stolen Keychain credentials into a JSON file directly on the infected device prior to transmission. The spyware also extracts Apple Notes databases and personal photos, which frequently contain seed phrases or account credentials stored by users. Similar to risks uncovered when Mark Karpelès found a spy chip in a hardware wallet, device-level compromises bypass standard application security.

Remote Execution and Exploitation History

The malware establishes a continuous remote control loop, pinging attacker-controlled servers every 15 seconds by default to receive new execution instructions. iVerify noted that operators can adjust this interval to search for specific files or initiate tailored collection routines without needing to re-compromise the device.

In March, Google's Threat Intelligence Group revealed that the underlying DarkSword framework utilized six vulnerabilities to exploit iPhones running iOS 18.4 through 18.7. That campaign involved commercial surveillance vendors targeting users across Saudi Arabia, Turkey, Malaysia, and Ukraine. Apple previously released security protections in 2025 and distributed iOS 18.7.7 on March 24, 2026, expanding device support on April 1.

Key Takeaways:

  • P7 DarkSword uses wallet_scan and wallet_extract commands targeting imToken and system Keychain files.
  • The spyware contacts command-and-control servers every 15 seconds to receive execution orders.
  • Google previously identified DarkSword using six vulnerabilities on iOS 18.4 to 18.7 across four countries.

Why It Matters

The discovery of P7 DarkSword underscores a critical shift in mobile threat vectors, where attackers exploit operating system flaws rather than breaking underlying cryptographic primitives or wallet apps directly. As warning signs mount over software-level vulnerabilities—echoing how AI exploits target code flaws before cryptography—investors relying on mobile hot wallets face elevated risks if device integrity is compromised. Keeping operating systems updated and avoiding plaintext credential storage in photo libraries or notes apps remain vital defense measures for self-custody users.

Read next