Researchers have revealed a new variant of iOS spyware named P7 DarkSword. This variant, named after the p7_ variable prefix used in the attacker's code, has been upgraded in terms of stealth, stability, and functionality. It reduces traces on the device by removing debug logs and minimizing process injection frequency, enabling bidirectional communication with the attacker's server every 15 seconds. It supports stealing photos, notes, app data, keychain information, encrypted wallet data, and arbitrary files, while also executing remote commands such as file reading, app enumeration, and JavaScript execution. Currently, the operators of this spyware continue to iterate and improve it.
