Researchers identify a more capable DarkSword iPhone spyware variant
Research published: 8 October 2026
Infection investigated: August 2026
Mobile-security company iVerify says it found a previously unseen variant of DarkSword while investigating an infection on a customer’s iPhone in August. Its 8 October report calls the variant P7 DarkSword. This is new analysis of a real case, rather than proof that every iPhone is currently being targeted.
According to iVerify, P7 leaves fewer obvious traces on the device than earlier versions. It can collect data from the iPhone’s Keychain, which stores passwords and other secrets, and look for cryptocurrency wallet data. It also contacts the attacker’s server for instructions, allowing the attacker to request files or information after the initial infection. The report describes capabilities found in the spyware; it does not show that each capability was used against every victim.
DarkSword uses an exploit chain aimed at particular older iOS releases. Previously published research identified iOS 18.4 through 18.7 as the affected range for the original chain. The P7 report adds detail about the malware installed after an attack, rather than announcing that fully updated iPhones have a new unpatched flaw.
The practical step for most owners is to install the latest iOS update available for their device and avoid delaying security updates. People at particular risk of targeted surveillance should seek specialist advice if they receive a credible compromise alert. Anyone who suspects a cryptocurrency wallet was exposed should get advice before moving funds or changing credentials on the same phone.






Comments