RESEARCHERS have disclosed a new variant of the DarkSword iOS exploit kit, named P7 DarkSword. Billed as a lighter-on-device variant, it patches tighter on-device stealth by removing debug logs, and it now also exfiltrates keychain data and crypto-wallet information, while enabling two-way command-and-control communication with the attacker’s infrastructure.
In the latest lineage, the implant is injected into SpringBoard and polls for commands every 15 seconds, sending a heartbeat and reporting installed apps, iCloud Keychain data, and data from wallet apps such as cryptocurrency wallets. Unlike earlier versions that copied the keychain database for exfiltration, P7 DarkSword now offloads keychain data to JSON on the device before transmission.
The kit is capable of a broad on-device command set, including filesystem inspection, file uploads, app containment enumeration, JavaScript execution inside the implant, and wallet- or note-related data harvesting. Notably, DarkSword’s production registry lists two CVEs newly associated with the framework: CVE-2025-24201, an out-of-bounds write in WebKit that can escape the browser sandbox, and CVE-2025-31200, a Core Audio memory corruption vulnerability enabling code execution.
The disclosure also ties the tool to multi‑actor campaigns across Saudi Arabia, Turkey, Malaysia, and Ukraine, with indicators of a Chinese-speaking exploitation‑as‑a‑service operation and open-directory activity linked to wallet theft (including BitKeep) and Coruna integration. Censys has pinpointed several open hosts tied to DarkSword/Coruna activity, underscoring the broader weaponisation and availability on the second-hand market.