P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Theft and Remote Commands
What Happened – Researchers disclosed a new variant of the DarkSword iOS exploit kit, dubbed P7 DarkSword. The kit trims its on‑device footprint, adds the ability to steal keychain entries and crypto‑wallet credentials, and establishes two‑way command‑and‑control (C2) communication with attacker infrastructure.
Why It Matters for Trust & Control Assurance
- Demonstrates a concrete failure of credential‑protection controls on mobile endpoints, the exact scenario a continuous control‑assurance program is built to detect and document.
- Requires defensible evidence that keychain hardening and access‑control policies are enforced, supporting audit readiness under frameworks such as NIST CSF 2.0.
- Highlights the need for real‑time monitoring of anomalous C2 traffic to provide timely assurance that controls remain effective.
Who Is Affected – Financial services firms handling crypto wallets, enterprises with large iOS device fleets, and mobile‑app developers whose products run on iOS.
Recommended Actions –
- Review and enforce hardware‑backed keychain policies via your MDM solution.
- Deploy continuous monitoring for suspicious outbound iOS traffic and C2 patterns.
- Update incident‑response playbooks to include mobile credential‑theft scenarios and collect relevant logs as audit evidence.
Source: The Hacker News
Technical Notes – P7 DarkSword leverages previously unknown iOS vulnerabilities to execute a low‑profile exploit, harvest keychain and crypto‑wallet data, and maintain bidirectional C2. No specific CVE IDs were disclosed at the time of reporting. Source: same