DarkSword 'P7': Leaked iOS exploit chain now stealing crypto wallet data

Security researchers have analyzed a new version of the DarkSword exploit chain, dubbed 'P7', which targets users on iOS 18.4–18.7. Previously available only to a select group of high-end clients, the malware is now being used for criminal purposes. Upon visiting compromised websites, often disguised as Chinese online casinos, an implant is injected into SpringBoard, where it decrypts the keychain and steals seed phrases and crypto wallet data. Experts from iVerify and Habr analysts have uncovered new infrastructure details, including the 'qqtime' delivery cluster and links to previous TA446 campaigns. This incident highlights the evolution of cyber-espionage tools as they transition from state-level actors to the arsenals of cybercriminals targeting user financial assets. The report provides a technical breakdown for mobile forensics and security professionals, correcting previous attribution errors regarding the March TA446 campaign.
This is a summary. Read the full article at the original source:
HabrRelated stories
Sam Labbé explores the critical distinction between ordering and authenticity in AI agent systems. While hash chains and DAGs effectively prove the se…
A recent TechRadar report clarifies the limitations of using a VPN while interacting with AI services like ChatGPT and Claude. While a VPN effectively…
Bitwarden, the popular open-source password management solution, has recently addressed community discussions regarding its dual licensing model. The…


