Executive Summary
In October 2026, cybersecurity researchers disclosed P7 DarkSword, an enhanced variant of the DarkSword iOS exploit kit that targets iPhones running iOS 18.4-18.7. This commercial exploit toolkit chains multiple iOS vulnerabilities to escape browser sandboxes, escalate to kernel privileges, and inject payloads into SpringBoard. P7 DarkSword introduces advanced capabilities including on-device cryptocurrency wallet theft, iCloud Keychain extraction, and bidirectional command-and-control communication. The kit has been deployed by multiple threat actors including Turkish surveillance vendor PARS Defense and Russian group Star Blizzard, with recent campaigns attributed to Chinese-speaking operators targeting victims across Saudi Arabia, Turkey, Malaysia, and Ukraine.
This incident represents the growing commoditization of mobile exploit kits following their leak into second-hand markets, enabling financially motivated cybercriminals to conduct sophisticated iOS attacks previously limited to nation-state actors.
Why This Matters Now
The proliferation of leaked commercial iOS exploit kits among cybercriminals demonstrates the urgent need for enhanced mobile security controls as sophisticated attack capabilities become accessible to lower-tier threat actors targeting high-value cryptocurrency assets.
Attack Path Analysis
The P7 DarkSword attack begins with victims visiting malicious websites hosting the iOS exploit kit, which chains multiple iOS vulnerabilities (CVE-2025-24201, CVE-2025-31200) to escape browser sandbox and gain kernel privileges. The malware injects into SpringBoard process to establish persistent command and control with 15-second polling intervals. Data exfiltration focuses on cryptocurrency wallets, iCloud Keychain, photos, and notes processed locally before transmission. The attack culminates in financial theft through cryptocurrency wallet compromise and potential broader device surveillance capabilities.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Victims visit malicious websites (fake Snapchat themes, Apple ID decoys) hosting P7 DarkSword exploit kit, which exploits CVE-2025-24201 (WebKit out-of-bounds write) and CVE-2025-31200 (Core Audio memory corruption) to escape iOS browser sandbox
Related CVEs
CVE-2025-24201
CVSS 10An out-of-bounds write vulnerability in the WebKit engine that allows an attacker to break out of the Web Content sandbox.
Affected Products:
Apple iOS – < 18.3.2
Apple iPadOS – < 18.3.2
Exploit Status:
exploited in the wildCVE-2025-31200
CVSS 9.8A memory corruption vulnerability in the Core Audio framework that allows code execution when processing an audio stream in a maliciously crafted media file.
Affected Products:
Apple iOS – < 18.4.1
Apple iPadOS – < 18.4.1
Exploit Status:
exploited in the wildCVE-2026-31001
CVSS 8.8A vulnerability in iOS 26 that is being actively exploited by threat actors using DarkSword exploit kit variants.
Affected Products:
Apple iOS – 26.x
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Drive-by Compromise
Exploitation for Client Execution
Exploitation for Privilege Escalation
Process Injection
Keychain
Data from Local System
Exfiltration Over C2 Channel
System Information Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security vulnerabilities are identified and managed
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
DORA – Identification and classification of ICT systems
Control ID: Article 8
CISA ZTMM 2.0 – Device Compliance and Health
Control ID: Device Security
NIS2 Directive – Risk management measures for network and information systems
Control ID: Article 21.2(a)
ISO 27001:2022 – Management of technical vulnerabilities
Control ID: A.8.8
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
P7 DarkSword's cryptocurrency wallet theft capabilities directly target financial mobile applications, extracting keychain data and wallet recovery phrases from iOS devices.
Computer/Network Security
Mobile malware evolution demonstrates advanced exploit kit proliferation requiring enhanced endpoint protection, threat detection capabilities, and iOS security framework updates.
Telecommunications
iOS exploit kit targeting mobile devices impacts telecom infrastructure security, requiring stronger mobile network protections and encrypted traffic monitoring capabilities.
Government Administration
State-sponsored threat actors using DarkSword against government targets necessitates enhanced mobile device management and zero trust segmentation for official communications.
Sources
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commandshttps://thehackernews.com/2026/10/p7-darksword-ios-exploit-kit-adds.htmlVerified
- DarkSword Variant Threat Researchhttps://www.iverify.com/blog/darksword-variant-threat-researchVerified
- DarkSword and Coruna Open Directory Finding Reporthttps://censys.com/blog/darksword-coruna-open-directory-finding-report/Verified
- Proliferation of Coruna and DarkSwordhttps://www.iverify.com/blog/proliferation-of-coruna-and-darkswordVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce the blast radius of P7 DarkSword iOS attacks by constraining lateral movement between cloud workloads and limiting egress channels for stolen cryptocurrency data exfiltration.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust architecture would likely constrain the initial attack's ability to reach backend cloud infrastructure and limit the scope of accessible cloud resources from compromised mobile devices
Control: Zero Trust Segmentation
Mitigation: Workload segmentation would likely limit the privileged access scope by constraining which cloud resources and data stores could be reached from the compromised mobile device context
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely constrain lateral movement between cloud workloads and limit the attacker's ability to traverse from mobile app backends to adjacent cloud services
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility controls would likely detect and constrain suspicious communication patterns between compromised devices and external C2 infrastructure across multiple cloud environments
Control: Egress Security & Policy Enforcement
Mitigation: Egress policy enforcement would likely constrain data exfiltration by blocking unauthorized outbound transfers of sensitive cryptocurrency and personal data to external attacker infrastructure
While financial theft may still occur from locally stored mobile data, the scope of cryptocurrency wallet compromise would likely be reduced through limited cloud storage access and constrained data synchronization channels
Impact at a Glance
Affected Business Functions
- Mobile Device Security
- Cryptocurrency Wallet Management
- Personal Data Protection
- Financial Transaction Security
Estimated downtime: N/A
Estimated loss: N/A
iCloud Keychain information, cryptocurrency wallet data including recovery phrases and balances, Apple Notes content, Photos, installed application data, device metadata, and filesystem information from compromised iOS devices across multiple countries including Saudi Arabia, Turkey, Malaysia, and Ukraine.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to detect and block unauthorized cryptocurrency wallet data exfiltration attempts to unknown C2 infrastructure
- • Deploy Multicloud Visibility & Control capabilities to identify suspicious 15-second polling patterns and anomalous mobile device traffic flows
- • Enable Encrypted Traffic (HPE) controls to prevent unencrypted transmission of sensitive keychain and wallet data during exfiltration phases
- • Establish Threat Detection & Anomaly Response systems to baseline normal mobile device communication patterns and alert on C2 beacon behaviors
- • Activate Cloud Native Security Fabric (CNSF) inline enforcement to inspect and block exploit kit delivery through malicious websites and fake application lures



