P7 DarkSword iOS exploit kit adds keychain and crypto-wallet theft
Malware Activity
Summary
Hide ▲
Show ▼
The P7 DarkSword variant now adds keychain theft and crypto-wallet theft while also enabling two-way C2 with attacker infrastructure, increasing the risk of stolen credentials and wallet abuse on compromised iPhones. The change makes the exploit kit more capable of harvesting high-value data and managing infected devices remotely.
Related Happenings
Chinese-speaking DarkSword exploitation-as-a-service operation with agent/reseller model
Threat Actor Meta
H score15
First: 09.10.2026 19:29
Last: 09.10.2026 19:29
Sources 1
How related:
"The platform runs a Chinese-speaking exploitation-as-a-service operation," Censys researcher Aidan Holland said. "The admin panel exposes an agent/reseller model, and a copy of the production server recovered 11 victim recovery phrases, 179 device loot directories, and a 75-account control-plane roster."
About this happening:
Researchers identified a Chinese-speaking DarkSword exploitation-as-a-service operation with an agent/reseller model, signaling a more organized criminal distribution ecos...
Chinese-speaking DarkSword exploitation-as-a-service operation with agent/reseller model
Threat Actor MetaHow related: "The platform runs a Chinese-speaking exploitation-as-a-service operation," Censys researcher Aidan Holland said. "The admin panel exposes an agent/reseller model, and a copy of the production server recovered 11 victim recovery phrases, 179 device loot directories, and a 75-account control-plane roster."
About this happening: Researchers identified a Chinese-speaking DarkSword exploitation-as-a-service operation with an agent/reseller model, signaling a more organized criminal distribution ecos...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware Activity
H score34
First: 03.08.2026 13:49
Last: 03.08.2026 13:49
Sources 1
About this happening:
The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
GHOSTBLADE credential-stealing activity on Apple iOS
Malware ActivityAbout this happening: The GHOSTBLADE malware is being deployed against Apple iOS devices to dump keychain, iCloud, and Wi‑Fi credentials and exfiltrate files, raising the risk of account ta...
CrashStealer analysis of client-side AES-GCM encryption and anti-analysis techniques
Technical Analysis
H score28
First: 14.07.2026 15:00
Last: 14.07.2026 15:00
Sources 1
About this happening:
Researchers published a technical analysis of CrashStealer that adds reusable detail on client-side AES-GCM encryption and layered anti-analysis behavior, making t...
CrashStealer analysis of client-side AES-GCM encryption and anti-analysis techniques
Technical AnalysisAbout this happening: Researchers published a technical analysis of CrashStealer that adds reusable detail on client-side AES-GCM encryption and layered anti-analysis behavior, making t...
CrashStealer macOS information stealer activity
Malware Activity
H score10
First: 13.07.2026 20:36
Last: 13.07.2026 20:36
Sources 1
About this happening:
CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
CrashStealer macOS information stealer activity
Malware ActivityAbout this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...
PromptSpy backdoor for Android with Gemini API automation
Malware Activity
H score22
First: 11.05.2026 16:02
Last: 11.05.2026 16:02
Sources 1
About this happening:
The PromptSpy backdoor for Android was highlighted for using Gemini APIs to automate device interaction, increasing the risk of unauthorized control on infected phones...
PromptSpy backdoor for Android with Gemini API automation
Malware ActivityAbout this happening: The PromptSpy backdoor for Android was highlighted for using Gemini APIs to automate device interaction, increasing the risk of unauthorized control on infected phones...
Timeline
-
09.10.2026 19:29 1 articles · 3h ago
DarkSword C2 server records two Chinese iOS devices polling a beacon page
Detection Ioc UpdateA DarkSword implant C2 server recorded two real Chinese iOS devices polling a beacon page every three seconds for several hours on September 6, 2026.
Show sources
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands — thehackernews.com — 09.10.2026 19:29
-
09.10.2026 19:29 1 articles · 3h ago
DarkSword C2 platform records device polling on September 15, 2026
Detection Ioc UpdateA DarkSword C2 platform was observed polling a device on September 15, 2026, showing the infrastructure remained active later in the month.
Show sources
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands — thehackernews.com — 09.10.2026 19:29
-
09.10.2026 19:29 2 articles · 3h ago
P7 DarkSword adds keychain and crypto-wallet theft
Initial DisclosureResearchers disclosed P7 DarkSword, a previously unseen DarkSword iOS exploit kit variant that reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with attacker infrastructure; the same reporting also ties the kit to DarkSword and Coruna components, open directories on five hosts, and exploit-registry entries for CVE-2025-24201 and CVE-2025-31200.
Show sources
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands — thehackernews.com — 09.10.2026 19:29
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands — thehackernews.com — 09.10.2026 19:29