Mobile-security firm iVerify has disclosed a new iPhone spyware variant it calls P7 DarkSword, found on a customer’s device in August 2026. The implant contacts its operator every 15 seconds by default. It pulls Keychain passwords and Apple Notes data. It also ships with a handler built to strip data out of the imToken crypto wallet app.

What P7 DarkSword steals
iVerify named the variant after a p7_ prefix the attacker used on variables in their modified code. The company says it investigated a DarkSword infection on a customer device that turned out to be a previously unseen variant.
The 15-second beacon is not fixed. A remote sleep command changes the interval, and an exit command shuts the agent down entirely. Keychain contents are converted to JSON on the phone before being sent out. Earlier DarkSword builds copied the raw keychain database wholesale.
Beyond that, iVerify documents handlers that collect:
- Crypto wallet data — a dedicated imToken handler, plus a separate wallet_scan routine that checks which wallet apps are installed
- Apple Notes — the SQLite databases along with their -wal and -shm companion files
- Photos — pulled from the device
- App inventory — a list of everything installed on the phone
- Filesystem sweep — a disk_scan handler that maps storage, uploads data in chunks, then deletes its own traces
Which iPhones are exposed is the open question
This is the part worth being careful about. iVerify’s post does not state which iPhone models or iOS versions are actually at risk today.
What it does show are artifacts baked into the malware’s own code. Every command-and-control request uses a hardcoded User-Agent identifying iOS 18.5. The indicator-of-compromise files carry names like rce_worker_18.4.js and sbx0_main_18.5. Those are component names chosen by the malware’s authors, not a published list of vulnerable builds.
iOS 18 is two annual releases behind the current iOS 27, since Apple’s numbering jumped from 18 to 26 in 2025. So the embedded fingerprints point at the iOS 18 generation. That is not confirmation that current iPhones are targets, and it is not confirmation that they are safe.
Why this one matters to ordinary owners
Strip away the handler names and the loss is concrete. A successful infection means saved passwords, personal notes and photos. For imToken users it also means the contents of a crypto wallet. Wallet theft is irreversible in a way a stolen password is not.
iVerify frames the variant as evidence of deliberate, skilled development rather than automated code generation:
P7 DarkSword shows that DarkSword operators are actively iterating on the implant. Unlike the many AI-assisted variants we observe, the P7 authors understood the code they were modifying: their changes reduced the implant’s footprint while extending its theft capabilities.
— iVerify
That smaller footprint is the uncomfortable detail. The operators traded visibility for reach, which is the opposite of what a defender wants. A wallet seed phrase saved in Apple Notes is exactly the kind of data this implant collects. This also follows a year in which Apple’s own spyware notifications reached 110 countries.
Source: iVerify





