New iPhone spyware variant targets crypto wallets, researchers warn

P7 DarkSword can scan for wallet apps and extract data, posing a risk to mobile cryptocurrency users

By LineZotpaper
Published
Read Time2 min
Security firm iVerify has disclosed a new variant of iPhone spyware, designated P7 DarkSword, that can remotely scan for cryptocurrency wallet applications and extract sensitive data from compromised devices, highlighting an emerging threat to mobile crypto holders.

Researchers at security firm iVerify have identified a new variant of iPhone spyware that specifically targets cryptocurrency wallets, according to a disclosure published on October 8. The malware, named P7 DarkSword, was discovered after an infection detected in August.

The variant includes two dedicated commands: wallet_scan, which searches compromised devices for installed wallet applications, and wallet_extract, designed to collect data associated with the imToken wallet, a multi-blockchain platform. Combined, these functions allow attackers to identify crypto users and retrieve wallet-related files.

Beyond wallet apps, P7 can also target Apple's Keychain password system, Apple Notes databases, photographs, and selected application files. The Keychain extraction process was modified in this variant to prepare data as a JSON file directly on the device before transmission, potentially giving attackers more immediately usable information.

The discovery underscores a growing risk for cryptocurrency users who store wallets on mobile devices. While obtaining wallet files or identifying an installed app does not automatically grant access to private keys, the malware could capture recovery phrases or credentials if users have stored them in notes or other accessible locations.

The report does not document specific cryptocurrency transfers or losses resulting from the spyware. However, the potential for unauthorized transactions depends on the sensitivity of the information successfully retrieved.

§

Analysis

Why This Matters

  • Cryptocurrency holders using mobile wallets face a new attack vector: spyware that targets the device rather than the wallet app itself.
  • The ability to scan for wallets and extract Keychain data could lead to theft of funds if recovery phrases or private keys are compromised.
  • As mobile crypto adoption grows, such threats may become more common, pressuring users to adopt additional security measures.

Background

Mobile cryptocurrency wallets are popular for their convenience, but they rely on the security of the underlying device. Spyware that gains device-level access can bypass app-level protections. iVerify regularly tracks mobile threats; the P7 DarkSword variant builds on earlier DarkSword versions with new crypto-focused capabilities.

Key Perspectives

[Security researchers]: The finding highlights that attackers are investing in targeted tools against crypto users. iVerify's disclosure aims to raise awareness and prompt users to review device security. [Crypto wallet users]: Users may need to take extra precautions, such as not storing recovery phrases on phones, using hardware wallets for significant holdings, and keeping devices updated. [Critics/Skeptics]: Without confirmed cases of theft from this specific spyware, some may question the immediate practical risk. However, the capabilities documented suggest a credible threat.

What to Watch

  • Whether Apple issues a security advisory or patch addressing the spyware.
  • Adoption of wallet-specific security features, such as biometrics or app-level encryption.
  • Reports of crypto thefts potentially linked to this or similar spyware variants.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe