New iPhone spyware can hunt for crypto wallets and extract their data every 15 seconds
Summary
Security firm iVerify identified P7 DarkSword, an iPhone spyware variant that can search for crypto wallet apps, collect files associated with imToken, and extract credentials from Apple Keychain. It can also gather notes and photos that may contain financial information. The spyware contacts an attacker-controlled server every 15 seconds by default for further instructions, enabling targeted collection after a device is compromised. Researchers reported no confirmed crypto theft, affected-user count, or financial losses. P7 is an evolution of spyware deployed after a successful compromise, not evidence of a new iOS vulnerability; Apple has patched vulnerabilities used in the documented DarkSword attack chain and advises users to update.
