Advanced iPhone spyware steals crypto wallet data every 15 seconds

A newly uncovered variant of iPhone spyware has been discovered by researchers, capable of remotely extracting sensitive credentials and cryptocurrency wallet data from infected devices.

Security firm iVerify revealed the existence of the malware, named P7 DarkSword, on October 8 following an analysis of an infection spotted in August. The new iteration features commands specifically aimed at cryptocurrency wallet applications, alongside the ability to harvest personal information, photos, and passwords.

This finding underscores a growing danger for mobile crypto users: threat actors who breach the host device can siphon off sensitive data without needing to exploit any flaws within the wallet app itself.

How the spyware targets cryptocurrency wallets

Based on the technical analysis conducted by iVerify, the P7 variant contains two specialized functions designed to locate and gather crypto-related data.

The initial command, wallet_scan, scans the compromised phone for installed wallet apps to help operators spot potential targets.

The subsequent function, wallet_extract, is built to pull data tied to imToken, a multi-chain cryptocurrency wallet.

Working in tandem, these commands enable attackers who have breached a phone to pinpoint crypto users and extract files associated with their wallets.

Additionally, the spyware targets Apple’s Keychain system, which houses authentication credentials, passwords, and other confidential data.

Whereas older versions of DarkSword copied and shipped the entire Keychain database to servers controlled by the attacker for processing, the P7 variant formats the extracted Keychain information into a JSON file locally on the victim’s device prior to transmission.

This adjustment alters how credentials are handled and may grant hackers immediate access to actionable information once it arrives at their command servers.

The threat goes beyond dedicated crypto applications.

P7 is also capable of gathering photographs, Apple Notes databases, and select app files. These repositories often house sensitive financial details, such as wallet credentials or recovery phrases, if users have saved them there.

That said, merely acquiring wallet files or finding an installed app does not instantly grant control over private keys. The execution of unauthorized transactions hinges on the specific data the malware manages to capture and whether it suffices to authorize transfers.

A more significant evolution is found in the spyware’s enhanced remote-control mechanisms.

Rather than depending entirely on a rigid, pre-programmed collection routine, P7 checks in with an attacker-controlled server every 15 seconds by default to fetch new instructions for the infected handset.

Operators can modify this polling frequency, hunt for specific files, and kick off additional data gathering tasks without needing to breach the device a second time.

Investigators also noted alterations aimed at improving reliability and evading detection.

These modifications involve cutting back on process injections, removing certain diagnostic logs, and leveraging browser storage to stop repeat exploitation attempts that might otherwise destabilize the phone.

Such changes point toward a pivot to more focused, long-term harvesting of sensitive data, which could allow bad actors to probe a victim’s financial dealings following an initial breach.

Even so, iVerify did not report proof of successful cryptocurrency theft, quantify total financial losses, or specify the scale of affected wallet users.

Apple’s earlier security fixes face an evolving threat

This discovery arrives on the heels of ongoing efforts to neutralize DarkSword, an iPhone exploitation framework previously leveraged by various surveillance groups.

In March, the Threat Intelligence Group at Google disclosed that DarkSword chained together six vulnerabilities to compromise iPhones running select builds of iOS 18.4 through 18.7.

Google documented operations involving commercial spyware vendors alongside suspected state-sponsored actors targeting individuals in Turkey, Saudi Arabia, Ukraine, and Malaysia.

That framework permitted intruders to compromise devices via malicious web content and subsequently install software designed to pull personal and financial records, including crypto wallet information.

However, P7 represents a post-exploitation evolution of the malware rather than proof of a novel vulnerability within Apple’s operating system.

Apple has already patched the vulnerabilities tied to the documented DarkSword attack chain.

Per the company’s security guidance, the relevant defenses rolled out initially in 2025.

Apple subsequently launched iOS 18.7.7 on March 24, 2026, extending those protections to additional devices on April 1 to safeguard users stuck on older software versions.

Related Reading

Apple’s App Store promoted fake Bitcoin wallet that stole $1.8M after developer spent a year warning them

These safeguards remain critical because the techniques uncovered by iVerify rely on an attacker already breaching the device.

The October findings do not prove that P7 can bypass current iOS security updates, and researchers did not release a variant-specific breakdown detailing which patched versions might remain vulnerable.

Nevertheless, Apple advises users to install the latest software updates and turn on automatic updates, while Google’s prior work on DarkSword also suggested utilizing Lockdown Mode if updating is not feasible.

Leave a Reply

Your email address will not be published. Required fields are marked *