iVerify’s P7 DarkSword report describes a spyware variant installed after a successful DarkSword exploit chain—not a standalone new iOS flaw.
It can search for and send files, photos, Apple Notes and crypto-wallet data.
The report places iPhones running unpatched iOS 18.4–18.7 in scope, but does not identify the infected device’s version.
iVerify found P7 in August 2026, examining an infection on an iPhone of a financial institution employee. It does not say which version of iOS the device was running.
Which devices does it concern?
P7 can work on iPhones running iOS 18.4 to iOS 18.7, as long as the relevant Apple security patches are not installed. It is spread through malicious ads.
The spyware is installed after a successful attack with DarkSword, a chain of techniques that exploit security vulnerabilities. P7 itself does not exploit a new vulnerability in iOS. Apple had fixed the vulnerabilities associated with DarkSword in iOS 15.8.7, iOS 16.7.15, and iOS 18.7.7. It also made iOS 18.7.7 available for devices that could be upgraded to iOS 26, so that users could be protected without having to upgrade to the latest major version.
P7 compatibility goes up to iOS 18.7, while a previous variant tracked by iVerify went up to iOS 18.6. Other versions of DarkSword that Google had detected already supported iOS 18.7.
What can it do?
The P7 examines the Keychain data on the iPhone and sends it to the attackers, rather than first transferring the entire database for processing elsewhere. It communicates with their servers every 15 seconds, with the ability to change this interval remotely. Attackers can then give it commands to search the file system, retrieve files, upload photos, list installed apps, and collect notes from Apple Notes and app data.
According to iVerify, P7 leaves fewer traces than previous versions: it logs fewer events and interferes less with device processes. It also leverages browser storage to avoid retargeting the same device. The company notes that older infection indicators are no longer valid. It attributes the changes to substantive work by operators and not simple AI modifications.
The wider use of DarkSword
According to Google, DarkSword is used by commercial surveillance software vendors, as well as by groups suspected of being state-sponsored. Attacks have been recorded in Saudi Arabia, Turkey, Malaysia, and Ukraine. Google and iVerify had previously disclosed DarkSword in 2026 along with Coruna, a separate tool that targeted iOS versions 13 through 17.2.1.
Apple has released patches for the vulnerabilities associated with DarkSword. The recommended action is to install the latest version of iOS that your device supports.
Top comments (0)