hacker-news · Crawled Oct 9, 2026

P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands

6 IoCs 1 Actors 1 Malware 1 CVEs
Read original article ↗

AI Summary

P7 DarkSword is a new variant of the DarkSword iOS exploit kit that enhances stealth and data theft capabilities, including exfiltration of iCloud Keychain, cryptocurrency wallet data, and remote command execution on compromised iPhones. The kit leverages previously undocumented iOS vulnerabilities CVE-2025-24201 and CVE-2025-31200 to escape browser sandbox and achieve kernel-level privileges. It has been used in attacks targeting Saudi Arabia, Turkey, Malaysia, and Ukraine by multiple threat actors, including PARS Defense and Star Blizzard. Researchers also identified active C2 infrastructure and open directories linked to Chinese-speaking operators running exploitation-as-a-service with a focus on cryptocurrency theft.

AI-extracted · verify before operational use

Extracted Entities 3 found

Indicators of Compromise 6 extracted

Type Value Detail
IP 43[.]134[.]165[.]205 Details →
IP 166[.]88[.]95[.]90 Details →
IP 23[.]148[.]212[.]237 Details →
IP 47[.]102[.]192[.]23 Details →
IP 156[.]239[.]230[.]120 Details →
Domain 66ds[.]lol Details →

MITRE ATT&CK TTPs 17 techniques