New iPhone spyware can hunt for crypto wallets and extract their data every 15 seconds
iVerify’s P7 DarkSword report describes remote commands to collect imToken-related data after an iPhone is compromised. The post New iPhone spyware can hunt for crypto wallets and extract their data every 15 seconds appeared first on CryptoSlate.
Researchers found a new iPhone spyware variant that can remotely extract cryptocurrency wallet data and sensitive credentials from compromised devices.
Security firm iVerify disclosed the malware, designated P7 DarkSword, on Oct. 8 after investigating an infection detected in August. The variant includes commands that specifically target cryptocurrency wallet apps and can collect passwords, photos, and personal information.
The discovery highlights an emerging risk for crypto holders who rely on mobile wallets: attackers who gain access to the underlying device could obtain sensitive information without exploiting a vulnerability in the wallet app itself.
According to iVerify's technical investigation, P7 includes two dedicated functions to identify and collect cryptocurrency-related information.
The first, wallet_scan, searches compromised devices for installed wallet applications, allowing attackers to identify potential targets.
The second, wallet_extract, is designed to collect data associated with imToken, a cryptocurrency wallet supporting multiple blockchain networks.
Together, the commands let attackers identify cryptocurrency users and retrieve wallet-related files after gaining access to their phones.
The spyware also targets Apple's Keychain, the system used to store passwords, authentication credentials, and other sensitive information.
Earlier DarkSword variants copied the Keychain database and transferred it to attacker-controlled infrastructure for processing.
P7 instead prepares extracted Keychain information as a JSON file directly on the compromised device before transmitting it.
This modification changes how the malware processes collected credentials and could give attackers more immediately usable information once the data reaches their servers.
The threat extends beyond crypto wallet applications themselves.
P7 can collect Apple Notes databases, photographs, and selected application files. These sources may contain sensitive financial information, including recovery phrases or wallet credentials if users have stored them there.
However, obtaining wallet files or discovering an installed application does not automatically establish control over its private keys. The potential for unauthorized transactions depends on what information the malware successfully retrieves and whether it is sufficient to authorize transfers.