← All posts

Security

The iPhone Exploit Chain Built for Spies Now Steals Keychains and Crypto Wallets. Apple Patched It in March

iVerify has found a new variant of the DarkSword iOS exploit chain, rebuilt to extract keychain entries and cryptocurrency wallet data instead of running surveillance. Every vulnerability it uses was fixed months ago, the last of them in iOS 26.3.

MAI
An Apple press photograph of a Mac, an iPhone 18 Pro, an Apple Watch Series 12, an iPad and an Apple Vision Pro arranged together on a desk.

iVerify's threat intelligence team published a report on October 8 describing a new variant of DarkSword, the iOS exploit chain that Google's Threat Intelligence Group disclosed in March. The variant does three things the original did not: it leaves less behind on the device, it keeps its foothold across browser sessions, and it steals the iPhone keychain and cryptocurrency wallet data directly on the phone. The chain underneath it has not changed at all. Apple fixed every vulnerability it uses, and the last of those fixes shipped in iOS 26.3.

That is the uncomfortable part. This is not a new hole in iOS. It is a patched hole, still being worked, by someone who has gone to the trouble of rebuilding the payload around a different kind of victim.

What iVerify found

The variant is named P7, after a variable prefix its author left in the code. iVerify began investigating it in August 2026, after a detection fired on a customer's device and looked slightly wrong — close to DarkSword, but not quite it. With the customer's consent the firm ran incident response, recovered forensic artifacts, and confirmed an unknown member of the family.

iVerify's summary of the changes is compact:

reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication

Each of those is a deliberate engineering choice. The stealth work removes diagnostic logging the earlier variant left in place and cuts down on process injections. The persistence work uses ordinary browser storage to avoid having to re-run the chain. The theft work is the most telling: rather than copying the whole keychain database off the device for later processing, P7 extracts keychain entries into structured data on the phone and sends only that. It also reaches for wallet application data by name.

The collection list is broad — keychain items, wallet data, Apple Notes databases, photos and photo-library metadata, the installed app inventory, and files from application sandboxes. iVerify notes that the author "had invested real effort in modifying it," which distinguishes P7 from the machine-assisted reskins the firm says it mostly sees.

The chain is six patched bugs

Google's Threat Intelligence Group published DarkSword on March 18, with Lookout and iVerify. It is a full chain written in JavaScript that strings six vulnerabilities together to run code with kernel privileges, and GTIG had observed it in use since at least November 2025. Its supported target range is iOS 18.4 through 18.7.

CVEComponentZero-day at the timeFixed in
CVE-2025-31277JavaScriptCoreNoiOS 18.6
CVE-2025-43529JavaScriptCoreYesiOS 18.7.3, 26.2
CVE-2026-20700dyldYesiOS 26.3
CVE-2025-14174ANGLEYesiOS 18.7.3, 26.2
CVE-2025-43510XNU kernelNoiOS 18.7.2, 26.1
CVE-2025-43520XNU kernelNoiOS 18.7.2, 26.1

GTIG attributed use of the chain to three unrelated clusters: UNC6748 against targets in Saudi Arabia, the Turkish commercial surveillance vendor PARS Defense against targets in Turkey and Malaysia, and UNC6353, a suspected Russian espionage group, against Ukrainian targets through compromised websites. All three deployed espionage payloads — message archives, location history, audio recording.

Proliferation, completed

That spread across unrelated actors was already the alarming thing about DarkSword in March. P7 is what the next stage looks like. The payload is no longer built to watch a person; it is built to drain accounts, and the device iVerify found it on belonged to an employee at a financial institution rather than to a journalist or a dissident.

iVerify made the argument in March, when it put the number of potentially vulnerable devices worldwide at roughly 270 million:

The risk is no longer limited to high-risk individuals; it now extends to any employee.

The firm's other claim from that post has aged well too — that device management tooling, which sees configuration and compliance rather than process behaviour, is "fundamentally blind to this type of zero-alert exploitation." A chain that runs from a web page and never asks the user for anything produces no prompt, no install, and no sign that anything happened.

What to do

Update. The version that closes all six bugs is iOS 26.3; iVerify recommends 26.3.1 or newer. Apple has also shipped security updates on its older branches for hardware that cannot run iOS 26, including iOS 18.7.7, 16.7.15, and 15.8.7, so an old iPhone is not an excuse to stay exposed. Where a device genuinely cannot be updated, Lockdown Mode is the fallback Google recommended in March.

For anyone running a fleet: the detection material is in iVerify's report, which publishes hashes, domains, and on-device artifact paths, and GTIG's post carries YARA rules and indicators for the original chain. A phone that comes back positive should be treated as a credential breach, not just a malware cleanup — the point of this variant is the keychain.

The patch has been available for months. Seven months after disclosure, the population still worth attacking is large enough that someone rewrote the payload to monetise it.

Sources: iVerify: Sleep, Beacon, Steal, Repeat — The Story of P7 DarkSword Variant · Google Threat Intelligence Group: DarkSword iOS exploit chain · iVerify: New DarkSword Exploit Confirms Mass iOS Attacks Are Now a Serious, Wide-Spread Business Risk · 9to5Mac

Keep reading