DarkSword spyware variant targets iPhone crypto wallets and Keychain
- —P7 DarkSword was found on a customer device in August 2026, iVerify says
- —The wallet_scan module looks for wallets; wallet_extract pulls imToken data
- —Infected devices poll attacker servers every 15 seconds by default
- —iVerify did not disclose infection numbers or confirmed crypto thefts
Why it matters: The finding shows that once an iPhone is compromised, attackers can reach not just wallet apps but also Keychain, notes and app files.
Source: TokenPost