|

New iPhone spyware can hunt for crypto wallets and extract their data every 15 seconds

P7 DarkSword’s remote command channel and reported wallet, app-file, Notes, photos and keychain collection capabilities on an already compromised iPhone. iVerify disclosed the variant October 8 after investigating an August 2026 infection; crypto transfers and losses are not documented or quantified in the report.

Researchers discovered a brand new iPhone spyware variant that can remotely extract cryptocurrency wallet data and delicate credentials from compromised gadgets.

Security agency iVerify disclosed the malware, designated P7 DarkSword, on Oct. 8 after investigating an an infection detected in August. The variant contains instructions that particularly goal cryptocurrency pockets apps and can gather passwords, images, and private info.

The discovery highlights an rising danger for crypto holders who depend on cell wallets: attackers who acquire entry to the underlying machine may get hold of delicate info with out exploiting a vulnerability within the pockets app itself.

How the spyware targets cryptocurrency wallets

According to iVerify’s technical investigation, P7 contains two devoted capabilities to determine and gather cryptocurrency-related info.

The first, wallet_scan, searches compromised gadgets for put in pockets functions, permitting attackers to determine potential targets.

The second, wallet_extract, is designed to gather data related to imToken, a cryptocurrency pockets supporting a number of blockchain networks.

P7 DarkSword’s remote command channel and reported wallet, app-file, Notes, photos and keychain collection capabilities on an already compromised iPhone. iVerify disclosed the variant October 8 after investigating an August 2026 infection; crypto transfers and losses are not documented or quantified in the report.

Together, the instructions let attackers determine cryptocurrency customers and retrieve wallet-related information after getting access to their telephones.

The spyware additionally targets Apple’s Keychain, the system used to retailer passwords, authentication credentials, and different delicate info.

Earlier DarkSword variants copied the Keychain database and transferred it to attacker-controlled infrastructure for processing.

P7 as an alternative prepares extracted Keychain info as a JSON file instantly on the compromised machine earlier than transmitting it.

This modification modifications how the malware processes collected credentials and may give attackers extra instantly usable info as soon as the data reaches their servers.

The risk extends past crypto pockets functions themselves.

P7 can gather Apple Notes databases, images, and chosen utility information. These sources might comprise delicate monetary info, together with restoration phrases or pockets credentials if customers have saved them there.

However, acquiring pockets information or discovering an put in utility doesn’t robotically set up management over its personal keys. The potential for unauthorized transactions will depend on what info the malware efficiently retrieves and whether or not it’s enough to authorize transfers.

A extra consequential growth is the spyware’s expanded remote-control functionality.

Rather than relying fully on a predetermined assortment course of, P7 communicates with an attacker-controlled server every 15 seconds by default, requesting directions that can be executed on the contaminated telephone.

Operators can modify that interval, search for particular information, and provoke extra assortment actions with out requiring one other machine compromise.

Researchers additionally recognized modifications supposed to make the spyware more durable to detect and extra dependable.

These embrace eliminating sure diagnostic logs, lowering the variety of course of injections, and utilizing browser storage to forestall repeated exploitation makes an attempt that would destabilize the contaminated machine.

The modifications point out a shift towards extra focused, sustained assortment of delicate info, doubtlessly permitting attackers to research a sufferer’s monetary exercise after gaining entry.

Still, iVerify didn’t disclose proof of a accomplished cryptocurrency theft, determine what number of pockets customers have been affected, or quantify any monetary losses.

Apple’s earlier safety fixes face an evolving risk

The discovery follows months of efforts to comprise DarkSword, an iPhone exploitation framework beforehand utilized by a number of surveillance operators.

In March, Google’s Threat Intelligence Group reported that DarkSword mixed six vulnerabilities to compromise iPhones working sure variations of iOS 18.4 by means of 18.7.

Google recognized campaigns involving business surveillance distributors and suspected state-backed attackers concentrating on customers in Saudi Arabia, Turkey, Malaysia, and Ukraine.

The framework allowed attackers to use weak gadgets by means of malicious net content material and subsequently deploy software program able to extracting private and monetary info, together with cryptocurrency pockets data.

However, P7 represents an evolution of the spyware deployed after a profitable compromise reasonably than affirmation of a brand new vulnerability in Apple’s working system.

Apple has already addressed the vulnerabilities related to the documented DarkSword exploitation chain.

According to the corporate’s security advisory, the related protections first turned accessible in 2025.

Apple later launched iOS 18.7.7 on March 24, 2026, increasing availability to extra gadgets on April 1 to guard customers nonetheless on older operating-system variations.

Related Reading

Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them


Those protections matter as a result of the capabilities iVerify uncovered rely on attackers first compromising a device.

The October investigation doesn’t set up that P7 can bypass the newest iOS safety updates, and researchers didn’t publish a variant-specific evaluation figuring out which patched variations stay weak.

Still, Apple recommends putting in the newest appropriate software program and enabling computerized updates, whereas Google’s earlier DarkSword analysis additionally advisable Lockdown Mode when updating just isn’t potential.

The submit New iPhone spyware can hunt for crypto wallets and extract their data every 15 seconds appeared first on CryptoSlate.

Similar Posts