• 5 mins read
  • Published

iPhone Spyware P7 DarkSword Hunts Crypto Wallets and Credentials

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

iPhone Spyware P7 DarkSword Hunts Crypto Wallets and Credentials EgonCoin © egoncoin.com
iPhone Spyware P7 DarkSword Hunts Crypto Wallets and Credentials © egoncoin.com

A new iPhone spyware variant scans for crypto wallets and pulls sensitive data every 15 seconds. The discovery puts mobile wallet users and their stored credentials in the crosshairs.

Security teams are tracking a fresh iPhone threat that zeroes in on digital wallets and personal credentials. The spyware, flagged by iVerify as P7 DarkSword, operates quietly on compromised devices and gives attackers a direct line to crypto assets managed through mobile wallets.

P7 DarkSword doesn't just lurk in the background. Its code actively searches for wallet apps, using a 'wallet_scan' function to spot targets. Once it finds a wallet, the malware can trigger a 'wallet_extract' command. This function specifically targets imToken, a popular multi-chain wallet, and tries to pull wallet files after attackers gain access. The wallet app itself doesn't need to have a known flaw for the spyware to go after user data.

Independent research found that DarkSword and Coruna malware variants have targeted major wallets including Coinbase, MetaMask, Trust Wallet, and Uniswap, highlighting the broad risk to the crypto ecosystem.

Analyst

The spyware's reach goes further than wallet apps. P7 DarkSword is built to grab Apple Keychain data, which holds passwords and authentication credentials. It packages this information as a JSON file and sends it to attacker-controlled servers. Attackers can use these credentials right away. The malware also scans Apple Notes, photos, and selected app files. If users have stored recovery phrases or wallet credentials in these places, those are at risk too. The spyware keeps a live connection to its command server, checking in every 15 seconds. Operators can tweak what the malware looks for, change how often it collects data, and launch new exfiltration attempts without having to reinfect the device.

P7 DarkSword's developers have worked to keep it under the radar. They stripped out some diagnostic logs, cut down on process injections, and use browser storage to avoid repeated exploitation that could crash the phone. These changes point to a shift toward longer-term, targeted surveillance. Attackers can watch a victim's financial activity over time. So far, iVerify hasn't confirmed any successful crypto thefts or pinned down how many users have been hit. The firm also hasn't shown whether P7 can get around Apple's latest iOS security patches.

P7 DarkSword surfaced after months of attempts to contain earlier DarkSword variants. Those earlier versions exploited iOS bugs to break into devices in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google's Threat Intelligence Group reported that DarkSword used six vulnerabilities to attack iPhones running iOS 18.4 and 18.7, pulling personal and financial data. Apple responded with security updates, first rolling out fixes in 2025 and then expanding them in iOS 18.7.7 in March 2026. There's no evidence yet that P7 can beat these latest patches. iVerify's findings highlight the need to keep devices updated and automatic security updates enabled. Google has advised users who can't update to turn on Lockdown Mode for extra protection.

According to Censys, the vulnerabilities exploited by DarkSword were patched in iOS 26.3, but devices running older versions-including iOS 18 and earlier-may remain at risk. This highlights the critical importance of timely software updates for all mobile wallet users.

Macworld

The full scope of the threat is still unclear, but the risk to mobile wallet users is real. If a device is compromised, attackers can grab sensitive credentials even if the wallet app itself is secure. This isn't just an iPhone problem or a single wallet provider's headache. As reported earlier, attackers are going after both centralized exchanges and individual wallets, shifting tactics as new defenses roll out.

iVerify first spotted the P7 DarkSword variant in August and disclosed it publicly in October. The firm hasn't released a breakdown of which iOS versions are still vulnerable, and there's no sign yet of widespread financial losses tied to this spyware. Apple continues to urge users to install the latest software and keep automatic updates on to cut exposure to known threats.

Storing recovery phrases, passwords, or private keys in unsecured spots like Apple Notes or unencrypted files leaves users exposed if their device gets infected. Even with strong wallet app security, the device itself is a weak link. Spyware like P7 DarkSword keeps raising the bar, forcing users to stay alert, update software quickly, and handle sensitive information with care.

Spyware aimed at crypto wallets fits a larger pattern in digital asset security. Attackers are focusing on endpoint compromise instead of protocol or smart-contract bugs. Device-level spyware sidesteps many traditional defenses by harvesting credentials, recovery phrases, or tokens stored elsewhere on the phone. That puts operational security-such as never saving sensitive info in unsecured apps-on the same level as keeping wallet software and operating systems current. As attackers shift tactics, users and developers have to keep rethinking their security playbook to keep digital assets safe.

Related articles