iPhone Spyware Targets Crypto Wallets Every 15 Seconds
Key Summary
A new iPhone spyware variant, P7 DarkSword, can remotely extract cryptocurrency wallet data and sensitive credentials from compromised devices, targeting Apple's Keychain and other applications every 15 seconds. The malware was discovered by iVerify, a security firm, and highlights an emerging risk for crypto holders who rely on mobile wallets. The spyware can collect passwords, photos, and personal information, and its remote-control capability allows attackers to adjust instructions and initiate collection activities without requiring another device compromise.
Emerging Risk for Crypto HoldersThe discovery of P7 DarkSword highlights an emerging risk for crypto holders who rely on mobile wallets. The malware can remotely extract cryptocurrency wallet data and sensitive credentials from compromised devices, targeting Apple's Keychain and other applications.
How the Spyware Targets Cryptocurrency WalletsAccording to iVerify's technical investigation, P7 includes two dedicated functions to identify and collect cryptocurrency-related information. The first, wallet_scan, searches compromised devices for installed wallet applications, allowing attackers to identify potential targets. The second, wallet_extract, is designed to collect data associated with imToken, a cryptocurrency wallet supporting multiple blockchain networks.
Expanded Remote-Control CapabilityThe spyware's expanded remote-control capability allows attackers to adjust instructions and initiate collection activities without requiring another device compromise. The malware communicates with an attacker-controlled server every 15 seconds by default, requesting instructions that can be executed on the infected phone.
Threat Beyond Crypto Wallet ApplicationsThe threat extends beyond crypto wallet applications themselves. P7 can collect Apple Notes databases, photographs, and selected application files. These sources may contain sensitive financial information, including recovery phrases or wallet credentials if users have stored them there.
Changes to DetectabilityThe spyware's modifications intended to make it harder to detect and more reliable include eliminating certain diagnostic logs, reducing the number of process injections, and using browser storage to prevent repeated exploitation attempts that could destabilize the infected device.