Crypto wallets face a new iPhone threat

Blockonomics
Bitbuy


Researchers found a new iPhone spyware variant that can remotely extract cryptocurrency wallet data and sensitive credentials from compromised devices.

Security firm iVerify disclosed the malware, designated P7 DarkSword, on Oct. 8 after investigating an infection detected in August. The variant includes commands that specifically target cryptocurrency wallet apps and can collect passwords, photos, and personal information.

The discovery highlights an emerging risk for crypto holders who rely on mobile wallets: attackers who gain access to the underlying device could obtain sensitive information without exploiting a vulnerability in the wallet app itself.

How the spyware targets cryptocurrency wallets

According to iVerify’s technical investigation, P7 includes two dedicated functions to identify and collect cryptocurrency-related information.

Ledger

The first, wallet_scan, searches compromised devices for installed wallet applications, allowing attackers to identify potential targets.

The second, wallet_extract, is designed to collect data associated with imToken, a cryptocurrency wallet supporting multiple blockchain networks.

P7 DarkSword’s remote command channel and reported wallet, app-file, Notes, photos and keychain collection capabilities on an already compromised iPhone. iVerify disclosed the variant October 8 after investigating an August 2026 infection; crypto transfers and losses are not documented or quantified in the report.P7 DarkSword’s remote command channel and reported wallet, app-file, Notes, photos and keychain collection capabilities on an already compromised iPhone. iVerify disclosed the variant October 8 after investigating an August 2026 infection; crypto transfers and losses are not documented or quantified in the report.

Together, the commands let attackers identify cryptocurrency users and retrieve wallet-related files after gaining access to their phones.

The spyware also targets Apple’s Keychain, the system used to store passwords, authentication credentials, and other sensitive information.

Earlier DarkSword variants copied the Keychain database and transferred it to attacker-controlled infrastructure for processing.

P7 instead prepares extracted Keychain information as a JSON file directly on the compromised device before transmitting it.

This modification changes how the malware processes collected credentials and could give attackers more immediately usable information once the data reaches their servers.

The threat extends beyond crypto wallet applications themselves.

P7 can collect Apple Notes databases, photographs, and selected application files. These sources may contain sensitive financial information, including recovery phrases or wallet credentials if users have stored them there.

However, obtaining wallet files or discovering an installed application does not automatically establish control over its private keys. The potential for unauthorized transactions depends on what information the malware successfully retrieves and whether it is sufficient to authorize transfers.

A more consequential development is the spyware’s expanded remote-control capability.

Rather than relying entirely on a predetermined collection process, P7 communicates with an attacker-controlled server every 15 seconds by default, requesting instructions that can be executed on the infected phone.

Operators can adjust that interval, search for specific files, and initiate additional collection activities without requiring another device compromise.

Researchers also identified modifications intended to make the spyware harder to detect and more reliable.

These include eliminating certain diagnostic logs, reducing the number of process injections, and using browser storage to prevent repeated exploitation attempts that could destabilize the infected device.

The changes indicate a shift toward more targeted, sustained collection of sensitive information, potentially allowing attackers to investigate a victim’s financial activity after gaining access.

Still, iVerify did not disclose evidence of a completed cryptocurrency theft, identify how many wallet users were affected, or quantify any financial losses.

Apple’s earlier security fixes face an evolving threat

The discovery follows months of efforts to contain DarkSword, an iPhone exploitation framework previously used by multiple surveillance operators.

In March, Google’s Threat Intelligence Group reported that DarkSword combined six vulnerabilities to compromise iPhones running certain versions of iOS 18.4 through 18.7.

Google identified campaigns involving commercial surveillance vendors and suspected state-backed attackers targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine.

The framework allowed attackers to exploit vulnerable devices through malicious web content and subsequently deploy software capable of extracting personal and financial information, including cryptocurrency wallet data.

However, P7 represents an evolution of the spyware deployed after a successful compromise rather than confirmation of a new vulnerability in Apple’s operating system.

Apple has already addressed the vulnerabilities associated with the documented DarkSword exploitation chain.

According to the company’s security advisory, the relevant protections first became available in 2025.

Apple later released iOS 18.7.7 on March 24, 2026, expanding availability to additional devices on April 1 to protect users still on older operating-system versions.

Related Reading

Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them

Those protections matter because the capabilities iVerify uncovered depend on attackers first compromising a device.

The October investigation does not establish that P7 can bypass the latest iOS security updates, and researchers did not publish a variant-specific assessment identifying which patched versions remain vulnerable.

Still, Apple recommends installing the latest compatible software and enabling automatic updates, while Google’s earlier DarkSword research also recommended Lockdown Mode when updating is not possible.



Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*