Technologies
Back
Cybersecurity & Privacy

DarkSword 'P7': Leaked iOS exploit chain now stealing crypto wallet data

Habr
Advertisement468 × 90
DarkSword 'P7': Leaked iOS exploit chain now stealing crypto wallet data

Security researchers have analyzed a new version of the DarkSword exploit chain, dubbed 'P7', which targets users on iOS 18.4–18.7. Previously available only to a select group of high-end clients, the malware is now being used for criminal purposes. Upon visiting compromised websites, often disguised as Chinese online casinos, an implant is injected into SpringBoard, where it decrypts the keychain and steals seed phrases and crypto wallet data. Experts from iVerify and Habr analysts have uncovered new infrastructure details, including the 'qqtime' delivery cluster and links to previous TA446 campaigns. This incident highlights the evolution of cyber-espionage tools as they transition from state-level actors to the arsenals of cybercriminals targeting user financial assets. The report provides a technical breakdown for mobile forensics and security professionals, correcting previous attribution errors regarding the March TA446 campaign.

This is a summary. Read the full article at the original source:

Habr
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250