Researchers at security firm iVerify have identified a new variant of iPhone spyware that specifically targets cryptocurrency wallets, according to a disclosure published on October 8. The malware, named P7 DarkSword, was discovered after an infection detected in August.
The variant includes two dedicated commands: wallet_scan, which searches compromised devices for installed wallet applications, and wallet_extract, designed to collect data associated with the imToken wallet, a multi-blockchain platform. Combined, these functions allow attackers to identify crypto users and retrieve wallet-related files.
Beyond wallet apps, P7 can also target Apple's Keychain password system, Apple Notes databases, photographs, and selected application files. The Keychain extraction process was modified in this variant to prepare data as a JSON file directly on the device before transmission, potentially giving attackers more immediately usable information.
The discovery underscores a growing risk for cryptocurrency users who store wallets on mobile devices. While obtaining wallet files or identifying an installed app does not automatically grant access to private keys, the malware could capture recovery phrases or credentials if users have stored them in notes or other accessible locations.
The report does not document specific cryptocurrency transfers or losses resulting from the spyware. However, the potential for unauthorized transactions depends on the sensitivity of the information successfully retrieved.