DarkSword Gets an Upgrade: Why Updating Your iPhone Still Matters

The latest DarkSword variant is stealthier, but Apple’s current patches still hold the line
A futuristic, conceptual 3D render of an iPhone being sliced by a digital, glowing blue sword, representing the DarkSword exploit.
Text Size
- +

Toggle Dark Mode

It seems the nasty DarkSword malware that was unearthed by security researchers earlier this year is not only still making the rounds — it’s evolving.

Unlike many iPhone exploits, the real danger of DarkSword wasn’t merely its ability to wage attacks on unpatched iPhones; it was the fact that it could be deployed by even the most inept of bad actors.

DarkSword was basically a ready-made hacking toolkit made up of a collection of HTML and JavaScript files that worked “out of the box” with no more expertise required than the ability to host files on a web server.

This Limited-Time Microsoft Office Deal Gets You Lifetime Access for Just $39

Sick and tired of subscriptions? Get a lifetime license for Microsoft Office Home and Business 2021 at a great price!

Just last week, we saw a dangerously fake “iPhone Duo Pre-Order” page pop up as a delivery mechanism for DarkSword. Simply opening the page in Safari on an unpatched iPhone or iPad was enough to pick up the malware.

The only saving grace is that “unpatched” in this case means devices running versions of iOS that pre-date March 24, 2026. Apple patched against DarkSword in iOS 26.4, iOS 18.7.7, iOS 16.7.15, and iOS 15.8.7 (and the equivalent iPadOS releases). No patches were released for previous iOS releases, but that’s because the exploits only work against devices running iOS 13 or later, all of which can be updated to at least iOS 15.8.7.

These updates also patched another exploit toolkit dubbed Coruna, which had targeted devices running iOS 13 through iOS 17.2.1, while DarkSword explicitly targeted iPhones running iOS 18.4 through iOS 18.7 — although other versions may have been vulnerable.

According to Google’s Threat Intelligence Group, DarkSword was initially used by “multiple commercial surveillance vendors and suspected state-sponsored actors” to break into the iPhones of users in Malaysia, Saudi Arabia, Turkey, and Ukraine.

Now, the folks at iVerify have discovered a new variant of DarkSword that they’ve dubbed P7, but the good news is that there doesn’t appear to be anything to worry about just yet, as there’s no evidence it’s able to compromise devices that have been patched against previous variants.

In August 2026 we investigated a DarkSword infection that turned out to be a previously unseen variant, which we call P7 DarkSword. The name P7 comes from the threat actor’s use of the p7_ variable prefix in modifications to original DarkSword’s code. Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure. This post describes the investigation, the variant’s capabilities, and the indicators that can be used to detect it.

iVerify

P7 DarkSword is notable mostly for the fact that it’s the first time this one has been observed. iVerify initially discovered it in August while investigating an infection on one of its customers’ devices. After digging into it, they were able to confirm this was not only an unknown variant, but a refined version that’s stealthier, more stable, and more sophisticated than the earlier ones.

More significantly, while most of the DarkSword variants that security researchers have seen over the past few months have been AI vibe-coded, P7 DarkSword appears to have been specifically hand-crafted by human architects, who “invested real effort in modifying it” and “demonstrated competence” in doing so.

Again, Apple’s defenses against DarkSword appear to be holding. iOS 18.7.7, iOS 26.4, and iOS 27 — and newer versions of each of those — remain fully protected against DarkSword. However, this just emphasizes even more strongly why it’s never a good idea to sit still on iOS updates. Nearly all of them include fix security vulnerabilities, and there’s always someone out there looking for new ones to exploit.

Sponsored
Social Sharing