// 9TO5MAC — MOBILE & WEB
Researchers uncover new DarkSword spyware variant affecting unpatched iPhones
iVerify released a report today detailing P7 DarkSword, a new variant of the malware associated with the DarkSword iPhone exploit chain uncovered earlier this year. Here are the details.
Earlier this year, Google and iVerify revealed two sophisticated iPhone hacking tools known as Coruna and DarkSword, both of which chained multiple iOS vulnerabilities to compromise devices running outdated system versions.
In DarkSword’s case, once an iPhone was compromised, attackers could deploy additional malware with access to sensitive data.
Coruna targeted devices running iOS 13 through iOS 17.2.1, while DarkSword affected iPhones running iOS 18.4 through iOS 18.7.
This led Apple to release system updates for the affected older iOS versions, including iOS 15.8.7, iOS 16.7.15, and iOS 18.7.7. Apple went as far as to take the unusual step of making iOS 18.7.7 available to devices that could install iOS 26, so users who elected not to update to the latest system version would also remain protected against DarkSword.
At the time, Google said DarkSword was being used by multiple commercial surveillance vendors and suspected state-sponsored actors, with attacks observed against targets in Saudi Arabia, Turkey, Malaysia, and Ukraine.
Today, iVerify announced the discovery of P7 DarkSword, a previously unseen variant it found while investigating an infection on the iPhone of an employee at a financial institution just two months ago.
In additional details shared with 9to5Mac, iVerify said P7 expands compatibility to iOS 18.7, up from iOS 18.6 in the earlier variant it had been tracking. Other DarkSword deployments observed by Google had already supported iOS 18.7.
The company also said the threat actor behind P7 is distributing it through malicious ads as part of watering-hole attacks, meaning victims do not necessarily appear to be individually targeted. Instead, users can be caught in broader campaigns simply by encountering malicious or compromised web content.
In August 2026 we investigated a DarkSword infection that turned out to be a previously unseen variant, which we call P7 DarkSword. The name P7 comes from the threat actor’s use of the p7_ variable prefix in modifications to original DarkSword’s code. Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure. This post describes the investigation, the variant’s capabilities, and the indicators that can be used to detect it._