iVerify’s October 8, 2026 report describes P7, a DarkSword variant whose analyzed sample processes keychain data on the device and includes cryptocurrency-wallet data collection handlers. iVerify identified the variant while investigating an infection on a customer’s device in August.
What P7 DarkSword’s analyzed sample does
The sample converts keychain data into JSON on the device before exfiltrating it. Earlier DarkSword variants sent a keychain database for processing on attacker infrastructure; P7’s reported on-device processing changes where that step happens.
The implant is injected into SpringBoard, an iOS system process, and communicates with attacker infrastructure through a two-way command-and-control (C2) channel. C2 lets an operator send tasks to an implant and receive information from it. The sample’s /beacon tasking poll runs every 15 seconds by default, and the interval can be changed remotely.
Its documented functions include collecting device and app information, photos, Notes and files, as well as scanning installed wallet apps. A separate handler is specifically for extracting wallet-related data from imToken. These are capabilities in the analyzed sample; the investigation concerned an infection on one customer device.
What the investigation covers
iVerify investigated the infection with the customer’s consent in August 2026 and published its analysis on October 8. The name P7 comes from the p7_ prefix in variables added to the DarkSword code.
The report also characterizes P7 as having a smaller on-device footprint, fewer process injections and fewer debug logs than variants iVerify usually observes. It describes browser localStorage as part of the sample’s approach to preventing re-exploitation.
The findings describe one investigated infection and the behavior of its analyzed sample. The report’s wallet-specific extraction handler names imToken.