Thursday morning, iVerify published what most ticket queues were not staffed to receive. A previously unseen DarkSword iOS variant, tagged P7. Smaller on the phone than the kits they usually see. Then it goes after the keychain, the crypto wallets, and a two-way channel back to the operator.
That is a cybersecurity problem your MDM enrollment screenshot does not cover. If your week was already booked around leftover FortiBleed hunting and the next Patch Tuesday window, bump a ticket. The interesting host is the phone in someone’s pocket.
P7 Cut Weight and Opened a Console
iVerify’s comparison is the part worth stealing for the briefing slide. P7 reduces its on-device footprint versus the DarkSword variants they usually observe. Less debris on disk means less for a mobile agent to trip over, and less for a rushed forensic image to explain when the user just wants the phone back. Quiet kits survive first-hour triage. That’s the point.
Then the kit goes where the money and the sessions live. On-device keychain theft is every saved Wi-Fi PSK, every app token, every password the user was too tired to type again. Crypto-wallet theft is a treasury function nobody put in the asset inventory because it lives in a personal app on a BYOD exception. You can run a clean laptop fleet and still lose the seed phrase that sat next to Outlook.
Two-way command and control is the operational change. A one-way implant exfiltrates and hopes. A kit that accepts remote commands lets the operator ask questions: which wallet, which seed, which session cookie, which second device is paired. You’re hunting an interactive session on a phone that can still show a green MDM check-in. Threat detection that only watches laptop process trees will miss that conversation.

Treat that C2 path like a live operator on a jump box. Once the kit can receive instructions, brute-force against the wallet UI becomes optional. The keychain already held the keys. The remote command is just the query. That’s a worse week than a noisy jailbreak that bricks the UI and announces itself.
The cybersecurity calendar still starts at the firewall
Help Net Security’s week-in-review this morning is the rest of the industry’s attention span in one line: FortiBleed is still active, and Patch Tuesday is coming. Edge appliances with standing bugs don’t retire because your change board got tired. They sit on the internet and wait. That work is real. Do it.

The mismatch is where the hours go. A lot of threat-protection spend still assumes the interesting remote code and the interesting login spray hit a firewall, a VPN, or a Windows box you can isolate with a GPO. P7 doesn’t need that path. The user already unlocked the phone. The kit is inside the device that holds Face ID, password-manager autofill, and the seed phrase.
Hospital CISOs in that same roundup get asked how they keep PHI off a fintech partner. Ask a parallel question in your shop. Which crypto wallet, which personal password manager, and which unmanaged iOS app sit on the same device as your SSO client. Defense in depth that stops at the laptop is a budget category. The phone already crossed your trust boundary the day you let it check mail.
Treat the iPhone like a privileged host
Start incident response on the phone the same day someone reports a weird profile, a jailbreak-looking prompt, a drained wallet, or a lock screen that started doing new things. Revoke SSO sessions from that device. Rotate every token that could have lived in the keychain. Treat saved Wi-Fi passwords and app secrets as stolen until you prove otherwise. If the user had a hot wallet on the same handset, assume the seed is gone and move remaining funds from a clean machine.
Immediate inventory is ugly and necessary. List devices that hold corporate identity and personal finance apps at the same time. Unsupervised iPhones, stale iOS builds, missing passcode rules, and config profiles you didn’t push are your first pass. Hunt DNS and HTTPS from those phones to infrastructure you cannot name. Two-way C2 looks like a phone having a conversation with a host you never enrolled.
Security hardening on mobile is still the boring controls, applied like you mean them. Supervised mode where you can legally require it. Block unsigned profiles. Short lock times. Encryption on. Measure update lag as a control failure. Ship device logs into the same threat detection pipeline you already trust for endpoints, and alert on new profiles, disabled lock, and jailbreak signals. That’s cyber security work you can do this quarter without buying a new category.
Write the combination into policy and keep it there. A device that holds your mail client doesn’t also run a hot wallet. Treasury moves to a hardware key or a machine that never sees SSO. Tabletop the CFO iPhone talking to an operator. If your playbook still opens with imaging the Windows box, you’ll spend the first four hours on the wrong host. Patch Tuesday still matters for FortiBleed leftovers. So does the phone you never put on the change calendar.
The console you cannot RDP
P7 is interesting because the authors spent engineering time getting smaller, then spent more time teaching the implant to listen. That’s product work. It means the operators using it expect to stay on the device long enough to issue follow-up commands. A quieter kit with a longer dwell time will outlast the first MDM health check, and your users will keep doing banking, travel, and side-project crypto on the same slab that holds the SSO cookie.
You already knew that overlap existed. The kit now knows it too. iVerify did you a favor by publishing the variant now, while most of the industry is still arguing about appliance patches. Use the window. Pull one executive device record this afternoon and ask whether anyone would notice two-way traffic from it. If the answer is a shrug, you have your next control, and you didn’t need a new vendor to find it.
Put the phone on the privileged-host list. Give it an owner in IR. Stop waiting for the laptop to explain a hole that opened in someone’s pocket.
Sources
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
- Week in review: FortiBleed is still active, Patch Tuesday forecast
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
