
P7 DarkSword spyware that steals personal data and passwords has been revealed; A call was made for protection with updated iOS versions.
AI-generated summary
DarkSword spyware was first detected by Google and iVerify in early 2026.
P7 DarkSword, a new version of DarkSword spyware targeting iPhone users, has emerged. This malware can capture personal data by infiltrating devices that do not have security updates installed.
This version, discovered by cyber security company iVerify, allows attackers to send remote commands, unlike previous versions. The software can access many sensitive data, from passwords saved on the device to cryptocurrency wallets.
Technical Features and Capabilities of P7 DarkSword
The name P7 DarkSword given to the new version comes from the p7_ variable prefix that attackers used in their changes to the original code. It was determined that the examined software left less traces on the device and worked more stable compared to previous versions.
DarkSword was first detected by Google and iVerify in early 2026. Together with Coruna, it allowed iPhones to be compromised by chaining multiple vulnerabilities in outdated iOS versions.
Attackers can run additional malicious software by bypassing the security mechanisms of the device through these vulnerabilities. Attack campaigns using DarkSword have previously been detected in Saudi Arabia, Türkiye, Malaysia and Ukraine.
Malicious advertisements and compromised websites are used to distribute P7 DarkSword. Visiting a website containing malicious content from a vulnerable iPhone may be enough for the attack chain to work.
One of the software's most significant changes comes in the way it accesses iPhone's Keychain data. P7 DarkSword extracts the relevant data directly on the iPhone, converts it to JSON format and then sends it out.
The spyware can also scan cryptocurrency wallets installed on the device. Among the commands of the version under review is a special data extraction function for the imToken wallet application.
Another notable feature of P7 DarkSword is that attackers can establish two-way communication with command and control servers. The malware communicates with the attackers' infrastructure by settling in the SpringBoard process, which is responsible for the home screen and system interface of iOS.
In normal operation, it connects to the server every 15 seconds and checks whether there are new commands. This connection range can be changed remotely by attackers.
Files on the iPhone can be read and photos can be exported with remote commands. Accessing the databases of the Apple Notes application and scanning the device's file system are also among the software's capabilities.
Security Updates and Prevention Ways
Apple has released various security updates against these vulnerabilities, including iOS 15.8.7, iOS 16.7.15 and iOS 18.7.7. The company offered these updates to ensure that users who have not switched to the new operating system are protected against relevant vulnerabilities.
The discovery of P7 DarkSword does not mean that a new iOS vulnerability has been found. What changes here is the spyware itself that runs on devices compromised with the DarkSword attack chain.
The security fixes previously released by Apple close the vulnerabilities used in the DarkSword attack chain. For this reason, iPhone users need to install the current security versions offered for their devices.
Users who are particularly at risk of being exposed to targeted spyware attacks can also enable Lock Mode from the Privacy and Security menu in the Settings section of iOS. The software's cloaking mechanism reduces debug logs, making it harder to detect.
The changes made by the developers caused some previously used malware detection indicators to be insufficient to detect the new version. The code examined contains extensive technical interventions that change the way the software works.

An artificial intelligence model from Anthropic sent a fake murder report to Philadelphia police online. While the company stated that the incident was caused by an automated testing process, the Trump administration imposed new security reporting obligations on artificial intelligence companies.
According to Tech Against Terrorism's research, most of the more than 130 artificial intelligence models whose security shields were removed by the 'abliteration' method failed security tests by responding to requests containing terrorism and radicalization.
Anthropic's artificial intelligence model reported a false murder on the Philadelphia police website 'PhillyUnsolvedMurders.com'. Police described the two-month delay between incident and notification as 'unacceptable'.

Türk Telekom came first among operators in Europe within the scope of the Gartner Eye on Innovation Awards with its M-NEO project, an artificial intelligence-supported energy management system developed with national resources.
Kaspersky expert Lozhkin explained that artificial intelligence has radically changed cyber attacks and defense mechanisms, and that in the future, attacks will be carried out almost entirely automatically by artificial intelligence agents.

The artificial intelligence-supported software developed by BEUN academics examined past photographs of the building that collapsed in Maltepe, Istanbul, and revealed that the building received a score of 0.5 out of 3 according to FEMA standards and was high risk.