Find notable cyber news and cases, enriched with sources, timelines, and signals.

P7 DarkSword iOS exploit kit adds keychain and crypto-wallet theft

Malware Activity
First reported
Last updated
Happening score
H score 16
1 unique sources, 1 articles

Summary

Hide ▲

The P7 DarkSword variant now adds keychain theft and crypto-wallet theft while also enabling two-way C2 with attacker infrastructure, increasing the risk of stolen credentials and wallet abuse on compromised iPhones. The change makes the exploit kit more capable of harvesting high-value data and managing infected devices remotely.

Related Happenings

Chinese-speaking DarkSword exploitation-as-a-service operation with agent/reseller model

Threat Actor Meta
H score15 First: 09.10.2026 19:29 Last: 09.10.2026 19:29 Sources 1

How related: "The platform runs a Chinese-speaking exploitation-as-a-service operation," Censys researcher Aidan Holland said. "The admin panel exposes an agent/reseller model, and a copy of the production server recovered 11 victim recovery phrases, 179 device loot directories, and a 75-account control-plane roster."

About this happening: Researchers identified a Chinese-speaking DarkSword exploitation-as-a-service operation with an agent/reseller model, signaling a more organized criminal distribution ecos...

GHOSTBLADE credential-stealing activity on Apple iOS

Malware Activity
H score34 First: 03.08.2026 13:49 Last: 03.08.2026 13:49 Sources 1

About this happening: The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...

CrashStealer analysis of client-side AES-GCM encryption and anti-analysis techniques

Technical Analysis
H score28 First: 14.07.2026 15:00 Last: 14.07.2026 15:00 Sources 1

About this happening: Researchers published a technical analysis of CrashStealer that adds reusable detail on client-side AES-GCM encryption and layered anti-analysis behavior, making t...

CrashStealer macOS information stealer activity

Malware Activity
H score10 First: 13.07.2026 20:36 Last: 13.07.2026 20:36 Sources 1

About this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...

PromptSpy backdoor for Android with Gemini API automation

Malware Activity
H score22 First: 11.05.2026 16:02 Last: 11.05.2026 16:02 Sources 1

About this happening: The PromptSpy backdoor for Android was highlighted for using Gemini APIs to automate device interaction, increasing the risk of unauthorized control on infected phones...

Timeline

  1. 09.10.2026 19:29 2 articles · 3h ago

    P7 DarkSword adds keychain and crypto-wallet theft

    Initial Disclosure

    Researchers disclosed P7 DarkSword, a previously unseen DarkSword iOS exploit kit variant that reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with attacker infrastructure; the same reporting also ties the kit to DarkSword and Coruna components, open directories on five hosts, and exploit-registry entries for CVE-2025-24201 and CVE-2025-31200.

    Show sources