iVerify says new DarkSword iPhone spyware variant scans phones for crypto wallets

Editorial illustration: A black scanning device projects pale blue beams onto a tilted smartphone, highlighting three gold wallet symbols among dark app tiles.

In brief

  • iVerify disclosed the P7 DarkSword spyware variant on Oct. 8 after investigating an August infection.
  • Two functions, wallet_scan and wallet_extract, look for wallet apps and imToken-related data.
  • P7 checks in with an attacker-controlled server every 15 seconds by default for instructions.
  • iVerify reported no confirmed crypto theft, no affected-user count and no financial losses.

Two functions built for wallets

iVerify's technical investigation found two dedicated functions for finding and collecting crypto-related information. The first, wallet_scan, searches compromised devices for installed wallet apps. The second, wallet_extract, is designed to collect data tied to imToken (a multi-chain crypto wallet).

Both run on a phone that's already been compromised. The report doesn't describe a flaw in the wallet app itself.

P7 also goes after Apple's Keychain, which stores passwords, authentication credentials and other sensitive data. Earlier DarkSword variants copied the Keychain database straight to attacker infrastructure, while P7 packages extracted Keychain information as a JSON file on the device before sending it out. It can also pull Apple Notes databases, photos and selected app files, and those can hold recovery phrases or wallet credentials if users stored them there.

Still, spotting a wallet app or grabbing its files doesn't automatically hand anyone control of private keys.

A 15-second check-in, not a 15-second heist

By default, P7 contacts an attacker-controlled server every 15 seconds to ask for instructions to run on the infected phone. That's a polling interval. Operators can change it, search for specific files and start more collection without having to compromise the device again.

Researchers also flagged changes meant to make the spyware harder to detect and more reliable. Those include removing certain diagnostic logs, cutting back on process injections and using browser storage to prevent repeated exploitation attempts.

What's missing matters too. iVerify didn't disclose evidence of a completed crypto theft, how many wallet users were affected or any financial losses.

DarkSword's track record

DarkSword is an iPhone exploitation framework that multiple surveillance operators had already used. In March, Google's Threat Intelligence Group reported that it combined six vulnerabilities to compromise iPhones running certain versions of iOS 18.4 through 18.7. Google identified campaigns involving commercial surveillance vendors and suspected state-backed attackers, including some that targeted users in Saudi Arabia and Turkey.

Those findings cover earlier DarkSword campaigns. They don't name whoever is running P7.

Frequently asked questions

Does P7 DarkSword extract crypto wallet data every 15 seconds?

No. According to iVerify's report as described by CryptoSlate, P7 contacts an attacker-controlled server every 15 seconds by default to request instructions. Operators can adjust that interval and start additional collection without compromising the device again.

What crypto-related data can P7 DarkSword collect?

P7 has a wallet_scan function that searches for installed wallet apps and a wallet_extract function designed to collect imToken-related data. It can also target Apple's Keychain, Apple Notes databases, photos and selected app files, which may hold recovery phrases or wallet credentials if users stored them there.

Has P7 DarkSword been linked to stolen crypto?

iVerify did not disclose evidence of a completed cryptocurrency theft, the number of affected wallet users or any financial losses. Obtaining wallet files or detecting a wallet app does not automatically give control over private keys.