P7 DarkSword: How to Detect & Block iOS Spyware & Wallet Theft

•By CyberNewsAI Threat Research Team•VERIFIED INTEL
P7 DarkSword iOS exploit kit targeting iPhones running iOS 18.x with SpringBoard injection and crypto wallet theft

SOC Briefing Summary :: Executive Key Takeaways

  • [01]Researchers uncovered P7 DarkSword, an advanced variant of the commercial iOS exploit kit weaponized in targeted attacks against iPhones running iOS 18.x.
  • [02]The kit chains WebKit (CVE-2025-24201) and Core Audio (CVE-2025-31200) exploits to escape browser sandboxes, escalate to kernel privileges, and inject into SpringBoard.
  • [03]P7 introduces on-device Keychain extraction into JSON, automated theft from 25+ cryptocurrency wallets, and a 15-second C2 loop; defenders must update iOS and deploy Mobile EDR.
SHARE INTEL:Reddit

Executive Summary

Mobile security researchers at iVerify, in collaboration with threat intelligence teams at Censys and Report URI, have uncovered P7 DarkSword—an evolved, highly sophisticated variant of the commercial DarkSword iOS exploit kit. First documented in March 2026 by Google's Threat Intelligence Group (GTIG) and Lookout, DarkSword originated as a commercial surveillance product sold to state-aligned and private cyber mercenary operators before proliferating across second-hand black markets and Chinese-speaking Exploitation-as-a-Service (EaaS) syndicates.

While historical DarkSword campaigns targeted iPhones running iOS 18.4 through 18.7 to deploy surveillance implants, the newly surfaced P7 iteration (identified by its developer codebase variable prefix p7_) marks a strategic evolution toward financial cybercrime and crypto asset drainage. P7 reduces its on-device forensic footprint by stripping debug logging over HTTP and syslog, abuses browser localStorage to suppress re-exploitation, extracts the iOS Keychain directly into structured JSON on-device, and injects its persistent implant into SpringBoard—the core iOS application and UI manager.

Operating with a bidirectional 15-second command-and-control (C2) polling loop, P7 DarkSword enables threat actors to execute arbitrary operating system commands, extract photos from /var/mobile/Media/DCIM, and systematically drain credentials, keystores, and seed recovery phrases from more than 25 mobile cryptocurrency wallets, including imToken and BitKeep. This intelligence dispatch provides a technical teardown of the exploit chain, maps adversary tactics to the MITRE ATT&CK framework, and details enterprise mitigation controls, mobile device management (MDM) hardening, and validated SOC detection rules.

---

Technical Vulnerability Analysis & Attack Chain

The P7 DarkSword exploit chain demonstrates the commodification of tier-one mobile zero-day capabilities, chaining browser sandbox escapes with kernel privilege escalation to hijack privileged iOS processes without requiring user jailbreaking.

Attack Chain Flow
// Attack Chain Flow

Root-Cause & Exploitation Mechanics

The P7 DarkSword kill chain transitions through web traffic manipulation, browser memory corruption, kernel compromise, and process injection:

  • Supply-Chain Web Traffic Hijacking (`ecomtrack[.]io`): Threat actors weaponized the expired domain of a defunct Czech e-commerce analytics startup (ecomtrack[.]io), re-registering it in mid-September 2026. Websites retaining legacy tracking tags execute malicious JavaScript that profiles mobile devices, fingerprints browser headers, cloaks against security crawlers, and silently redirects qualifying iPhone visitors to a deceptive cryptocurrency trading lure at chainmate[.]top.
  • WebKit Sandbox Escape (`CVE-2025-24201`): Upon landing, the target browser executes an exploit targeting an out-of-bounds write vulnerability within the WebKit engine (CVE-2025-24201, addressed by Apple in iOS 18.3.2). This memory corruption primitive allows the adversary to break out of the Safari Web Content sandbox and execute shellcode within the higher-privileged browser broker process.
  • Core Audio Memory Corruption (`CVE-2025-31200`): The chain integrates a secondary memory corruption exploit in Apple's Core Audio framework (CVE-2025-31200, addressed in iOS 18.4.1), triggered while parsing a maliciously crafted media audio stream. This flaw facilitates reliable code execution outside browser restrictions.
  • Kernel Privilege Escalation & SpringBoard Injection: Leveraging a chained kernel memory vulnerability, the exploit achieves arbitrary kernel read/write primitives, disabling iOS code-signing enforcement (CS_KILL/CS_HARD) and sandbox entitlements. The implant is injected directly into SpringBoard (/System/Library/CoreServices/SpringBoard.app), the daemon responsible for application launching, window management, and hardware event handling.
  • On-Device Keychain Parsing into JSON: Prior DarkSword iterations exfiltrated raw keychain SQLite databases for offline cracking. P7 introduces an on-device extraction engine that interfaces directly with Apple Security framework APIs, dumping stored web passwords, Wi-Fi credentials, and application tokens directly into structured JSON records on the phone before transmission.
  • Automated Crypto Wallet Drainage (25+ Wallets): The implant queries app sandbox containers and app-group directories under /var/mobile/Containers/Data/Application/, targeting 25+ cryptocurrency wallet applications (including imToken and BitKeep). It automatically locates and extracts encrypted keystores, private keys, and plain-text mnemonic seed recovery phrases stored in application state files or Apple Notes databases (memo_scan).
  • Two-Way C2 Loop with 15-Second Polling: The SpringBoard implant establishes an encrypted HTTPS beaconing loop to C2 infrastructure (mertio[.]cc, 66ds[.]lol), polling every 15 seconds. Supported commands include execute_command (supporting CLI utilities like ls, cat, mkdir, rm, ps, memdump, netstat, whoami), disk_scan (recursively enumerating /), photos (harvesting camera rolls), and exec (evaluating arbitrary JavaScript within the implant runtime).

---

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
Initial AccessT1189Drive-by CompromiseHijacking expired analytics tracking scripts on web stores to deliver browser exploit lures.
ExecutionT1203Exploitation for Client ExecutionTriggering WebKit out-of-bounds write (CVE-2025-24201) and Core Audio flaw (CVE-2025-31200).
Privilege EscalationT1068Exploitation for Privilege EscalationChaining iOS kernel read/write primitives to bypass mobile sandbox boundaries.
Defense EvasionT1055Process Injection: SpringBoardInjecting spyware implant into the root iOS SpringBoard UI and application daemon.
Defense EvasionT1562.001Impair Defenses: Disable System LoggingEliminating debug HTTP traffic and suppressing syslog messages to evade forensic capture.
Credential AccessT1555.001Credentials from Password Stores: KeychainParsing on-device iOS Keychain entries into JSON format prior to exfiltration.
CollectionT1552.001Unsecured Credentials: Local FilesHarvesting cryptocurrency mnemonic recovery phrases and keystores across 25+ wallet apps.
Command & ControlT1071.001Application Layer Protocol: Web ProtocolsEstablishing 15-second HTTPS polling loops to adversary C2 servers (mertio[.]cc, 66ds[.]lol).

---

Threat Actor Profile & Campaign Attribution

The operational footprint of P7 DarkSword reflects the convergence of state-grade offensive tools and criminal financial operations:

  • Commercial Surveillance Origin & Proliferation: Originally developed as a commercial cyber-surveillance toolkit, DarkSword was observed in targeted espionage operations conducted by Turkish surveillance contractor PARS Defense (masquerading as Snapchat portals) and Russian threat actor Star Blizzard (COLDRIVER) targeting Saudi Arabia, Turkey, Malaysia, and Ukraine.
  • Exploitation-as-a-Service (EaaS) Chinese Infrastructure: Telemetry uncovered by Censys revealed open-directory infrastructure on five IP clusters operating a Chinese-language EaaS platform. An exposed production server at 156.239.230[.]120 uncovered 179 victim loot directories, 11 stolen recovery seed phrases, and an agent/reseller management portal.
  • Bundle Packaging (DS-Fusion / DarkCoruna): Threat actors have packaged DarkSword alongside Coruna—a complementary iOS exploit kit weaponized against iOS 13.0 to 17.2.1—creating DS-Fusion v1.0 on staging host 43.134.165[.]205 to deliver multi-generation iOS coverage. Analysis hosts (23.148.212[.]237) show active development targeting newer iOS builds (such as CVE-2026-31001).

---

Detection & SOC Mitigation Playbook

1. Concrete Remediation & Workarounds

Enterprise mobility administrators and security teams must implement immediate defense-in-depth measures:

Step 1: Enforce Immediate iOS Fleet Updates Beyond iOS 18.4.1 Baseline

Ensure all enterprise iPhones are updated beyond iOS 18.4.1/18.7 to neutralize the unpatched WebKit and Core Audio components:

QUERY / DETECTION_RULE
BASH / CLI
# Verify Apple iOS build version compliance via MDM query (Apple Device Management API)
curl -X GET "https://mdm.enterprise.com/api/v1/devices" \
  -H "Authorization: Bearer $MDM_TOKEN" \
  | jq '.devices[] | select(.os_version < "18.4.1") | {device_id: .id, user: .assigned_user, os: .os_version}'

Enforce automated zero-touch patching policies via Microsoft Intune, Jamf Pro, or VMware Workspace ONE.

Step 2: Enforce Apple Lockdown Mode for High-Value Executive & Treasury Accounts

Lockdown Mode hardens device defenses against sophisticated web and media exploits:

  • Disables Just-In-Time (JIT) JavaScript compilation in WebKit.
  • Blocks complex web fonts and unapproved media parsing formats.
  • Restricts incoming configuration profiles and WebAssembly execution.

Step 3: Implement Mobile Threat Defense (MTD) Network Inspection

Deploy on-device network proxying (Zscaler, Lookout, Jamf Trust) to inspect mobile outbound traffic, sinkholing known DarkSword C2 domains (mertio[.]cc, 66ds[.]lol, chainmate[.]top, ecomtrack[.]io).

2. Network & Perimeter Defenses

  • Outbound Beaconing Alerting: Configure enterprise Secure Web Gateways (SWG) to detect mobile endpoints establishing recurring HTTPS POST/GET connections on precise 15-second or 30-second polling cadences.
  • DNS Sinkholing: Implement immediate sinkholes for the five Censys-identified EaaS server IP ranges and exploit staging domains.

3. Endpoint Detection & Hunting Query

Validated Sigma Rule (YAML)

QUERY / DETECTION_RULE
SIGMA / YAML
title: P7 DarkSword iOS WebKit Sandbox Breakout and SpringBoard Injection
id: a749b102-3c81-4f91-b192-5e82109df410
status: experimental
description: Detects network beaconing, abnormal SpringBoard socket initialization, or mobile EDR telemetry matching P7 DarkSword iOS exploit kit indicators.
author: CyberNewsAI Threat Research Team
date: 2026/10/11
references:
  - https://thehackernews.com/2026/10/p7-darksword-ios-exploit-kit-adds.html
logsource:
  category: network_connection
  product: mobile_edr
detection:
  selection_domains:
    destination_hostname|endswith:
      - 'mertio.cc'
      - '66ds.lol'
      - 'chainmate.top'
      - 'ecomtrack.io'
  selection_ips:
    destination_ip:
      - '43.134.165.205'
      - '166.88.95.90'
      - '23.148.212.237'
      - '47.102.192.23'
      - '156.239.230.120'
  selection_springboard:
    initiating_process_path|endswith:
      - '/System/Library/CoreServices/SpringBoard.app/SpringBoard'
    connection_frequency_interval_seconds:
      - 15
      - 30
  condition: selection_domains or selection_ips or selection_springboard
falsepositives:
  - Legitimate Apple push notification services (APNs) communicating on official Apple ASN subnets (AS714)
level: critical
tags:
  - attack.execution
  - attack.t1203
  - attack.t1055
  - attack.t1071.001

Microsoft Sentinel / Defender KQL Hunting Query

QUERY / DETECTION_RULE
SENTINEL / KQL
// Microsoft Sentinel: Hunting for P7 DarkSword C2 Beaconing and Compromised Mobile Endpoints
// Identifies corporate devices establishing connections to documented DarkSword infrastructure
let MaliciousDomains = dynamic(["mertio.cc", "66ds.lol", "chainmate.top", "ecomtrack.io"]);
let MaliciousIPs = dynamic(["43.134.165.205", "166.88.95.90", "23.148.212.237", "47.102.192.23", "156.239.230.120"]);
DeviceNetworkEvents
| where TimeGenerated >= ago(14d)
| where RemoteUrl has_any (MaliciousDomains) or RemoteIP in (MaliciousIPs)
| project TimeGenerated, DeviceName, DeviceId, ActionType, RemoteIP, RemoteUrl, RemotePort, InitiatingProcessFileName
| summarize ConnectionCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by DeviceName, RemoteIP, RemoteUrl
| order by ConnectionCount desc

Splunk Hunting Query (SPL)

QUERY / DETECTION_RULE
SPLUNK / SPL
index=* (sourcetype="pan:traffic" OR sourcetype="cisco:asa" OR sourcetype="suricata")
| where (match(dest_host, "(?i)(mertio\.cc|66ds\.lol|chainmate\.top|ecomtrack\.io)") OR dest_ip IN ("43.134.165.205", "166.88.95.90", "23.148.212.237", "47.102.192.23", "156.239.230.120"))
| bin _time span=15m
| stats count values(src_ip) as affected_devices values(dest_port) as dest_ports by _time, dest_host, dest_ip
| eval alert_severity="CRITICAL: P7 DarkSword iOS Exploit Kit C2 Activity Detected"
| sort - count

---

Indicator TypeValue / PatternOperational Context
Hijacked Analytics Domainecomtrack[.]ioExpired Czech analytics domain re-registered to inject exploit lures on retail sites.
Exploit Lure Domainchainmate[.]topBogus crypto trading platform serving P7 DarkSword iOS exploit chain.
C2 Domainmertio[.]ccPrimary C2 server handling implant tasks (30s polling, exec, photos, spy).
C2 Domain66ds[.]lolSecondary C2 domain identified in wild campaigns targeting BitKeep wallets.
DS-Fusion v1.0 Host43.134.165[.]205Staging server distributing combined DarkSword and Coruna exploit bundle.
C2 Server Host166.88.95[.]90Active beaconing host observed receiving iOS implant heartbeats.
Exploit Development Host23.148.212[.]237Server hosting active development for iOS 26 exploit chains (CVE-2026-31001).
Coruna Staging Host47.102.192[.]23Staging infrastructure for companion Coruna cryptocurrency stealer kit.
EaaS Control Plane Host156.239.230[.]120Chinese-speaking exploitation-as-a-service panel with 179 victim loot folders.
Target VulnerabilityCVE-2025-24201WebKit out-of-bounds write flaw enabling browser sandbox breakout.
Target VulnerabilityCVE-2025-31200Core Audio memory corruption flaw enabling arbitrary code execution.
Target VulnerabilityCVE-2026-31001Unpatched vulnerability targeted in next-generation iOS 26 exploit research.
Compromised ProcessSpringBoardPrivileged iOS process injected to maintain C2 beaconing and command execution.
Targeted WalletsimToken, BitKeep, 25+ WalletsMobile crypto apps targeted for automated keystore and mnemonic extraction.
Indicators of Compromise (IOCs)
14 Identified
Hijacked Analytics Domainecomtrack[.]io
Exploit Lure Domainchainmate[.]top
C2 Domainmertio[.]cc
C2 Domain66ds[.]lol
DS-Fusion v1.0 Host43.134.165[.]205
C2 Server Host166.88.95[.]90
Exploit Development Host23.148.212[.]237
Coruna Staging Host47.102.192[.]23
EaaS Control Plane Host156.239.230[.]120
Target VulnerabilityCVE-2025-24201 (WebKit Sandbox Breakout)
Target VulnerabilityCVE-2025-31200 (Core Audio Memory Corruption)
Target VulnerabilityCVE-2026-31001 (Next-Gen iOS Exploit Research)
Compromised ProcessSpringBoard
Targeted WalletsimToken, BitKeep, 25+ Mobile Wallets
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE