P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Theft and Remote Commands

Summary
Researchers describe P7 DarkSword, an iOS exploit-kit variant that steals keychain and crypto-wallet data and accepts remote commands. Related reporting links DarkSword and Coruna to multiple operators and cryptocurrency-theft activity.
Key points
- P7 DarkSword reduces its on-device footprint and prepares keychain data as JSON on the iPhone before exfiltration.
- The implant runs in SpringBoard, polls its command-and-control infrastructure every 15 seconds, and sends heartbeats and installed-app lists.
- It can transmit iCloud Keychain data and information from apps including Notes, Photos, and cryptocurrency wallets.
- DarkSword chains iOS vulnerabilities to escape the browser sandbox, gain kernel privileges, and inject its payload; earlier reporting documented targeting of iOS 18.4–18.7.
- The kit has been used in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine, with activity attributed to multiple threat actors.
- Censys found open directories hosting DarkSword- and Coruna-related components and reported recovered victim recovery phrases, device loot directories, and a control-plane roster.
- Censys also identified a separate China-based operator using the kit and targeting the BitKeep wallet.
Article Details
- Attack Vectors
- Chains iOS vulnerabilities to escape the browser sandbox, escalate to kernel privileges, and inject the payload into SpringBoard.
- Uses fake Snapchat-themed websites and fake invitation lures to deliver the exploit kit.
- Polls attacker infrastructure for commands and exfiltrates keychain, iCloud Keychain, application, and cryptocurrency-wallet data.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 66ds[.]lol | C2 server used by a separate China-based operator running the kit. |
| IPV4 | 156[.]239[.]230[.]120 | Platform suspected by Censys to be operated by a Chinese-speaking threat actor for cryptocurrency wallet theft. |
MITRE ATT&CK
T1041 · Exfiltration Over C2 ChannelThe implant transmits stolen keychain and application data to attacker infrastructure.T1055 · Process InjectionThe payload is injected into the SpringBoard process.T1068 · Exploitation for Privilege EscalationThe exploit chain uses iOS vulnerabilities to escape the browser sandbox and escalate to kernel privileges.T1555.001 · KeychainP7 DarkSword extracts keychain data and transmits iCloud Keychain information.
People
Threat Actors
COLDRIVERIdentified in the article as an alias of Star Blizzard, which reportedly used DarkSword with fake invitation lures.PARS DefenseTurkish commercial surveillance vendor reported to have used DarkSword in attacks via a fake Snapchat-themed website.Star BlizzardRussia-aligned threat actor reported to have used DarkSword with fake invitation lures; the article identifies COLDRIVER as an alias.
Malware
Corunaas Censys said it identified open directories on five hosts carrying components related to DarkSword and Coruna, another iOS exploit kit uncovered this year as weaponized in attacks aimed at iPhone models running iOSDarkSwordCybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.P7 DarkSwordCybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.
Vendors
Products
Apple Notesof installed applications, and transmit iCloud Keychain information and data from applications like Apple Notes, Photos, and cryptocurrency wallets.BitKeepthe wild against its own C2 server at "66ds[.]lol," while including a new cryptocurrency wallet target (BitKeep) not present in the open-directory set. The findings once again highlight the proliferation of the kitiOSCybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword.Photosapplications, and transmit iCloud Keychain information and data from applications like Apple Notes, Photos, and cryptocurrency wallets.SpringBoardto escape the browser sandbox, escalate to kernel privileges, and inject the main payload into SpringBoard, the iOS process that handles app launches and the home screen. The exploit chain is assessed to be a
Countries
ChinaCensys said it also detected a separate China-based operator running the same kit in the wild against its own C2 server at "66ds[.]lol," while including a new cryptocurrency wallet target (BitKeep) not present in theMalaysiaThe exploit kit has been put to use in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine by multiple threat actors, including a Turkish commercial surveillance vendor named PARS Defense via a fakeSaudi ArabiaThe exploit kit has been put to use in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine by multiple threat actors, including a Turkish commercial surveillance vendor named PARS Defense via a fakeTurkeyThe exploit kit has been put to use in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine by multiple threat actors, including a Turkish commercial surveillance vendor named PARS Defense via a fakeUkraineThe exploit kit has been put to use in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine by multiple threat actors, including a Turkish commercial surveillance vendor named PARS Defense via a fake