Red Team

Upgraded DarkSword iPhone exploit kit served via dead analytics tag

A newer DarkSword iOS exploit build is reaching shoppers via a lapsed analytics domain still embedded in online stores. What UK firms should do.

Illustration of a target over a smartphone representing the DarkSword iPhone exploit kit

An upgraded build of the DarkSword iPhone exploit kit is reaching shoppers through an analytics tag that online stores forgot to remove after the vendor folded. The campaign shows how old third-party JavaScript can turn an ordinary retail website into a way to deliver spyware.

What happened

On 8 October 2026 the mobile security firm iVerify published its analysis of a DarkSword variant it calls P7. The name comes from a “p7_” prefix in the modified code. iVerify found it in August while investigating an unusual alert on a customer’s iPhone.

A day later, Scott Helme of Report URI published research into how a newer build reaches its victims. The route starts with ecomtrack.io, which used to belong to a Czech start-up selling e-commerce analytics. The company disappeared, but its tag stayed in store templates. Someone re-registered the expired domain on 15 September 2026, and from then on every store still loading the script was serving that person’s code. Report URI updated its post on 9 October: two of the recovered modules are byte-for-byte matches for iVerify’s P7 samples. The build it found appears to be later (v24), with different infrastructure and more wallet targets.

DarkSword itself is not new. Google Threat Intelligence Group, iVerify and Lookout first described it in March 2026 as an exploit chain for iOS 18. According to The Hacker News, earlier deployments were tied to a Turkish surveillance vendor, PARS Defense, and to a Russia-aligned group. There is no published evidence linking the P7 variant or the ecomtrack.io campaign to either of them. Report URI says the activity looks financially motivated and names no operator.

The technical picture

The delivery chain has three stages, and each one filters out anyone who might be a researcher. First, the re-registered domain serves a small script of about 2KB. It looks for crawlers, bots and headless browsers, then sends a profile of the device back to its server. In Report URI’s tests, visitors from datacentre and VPN addresses got nothing back. Some residential visitors got a redirect on their first visit and nothing afterwards.

Second, visitors who pass that check go to traffic brokers. Visitors who look like real people are sold on: to an investment scam, an online casino, or a fake AI crypto trading site called chainmate.top. The same server runs the kit from two more domains: a lapsed lead-generation SDK and a script injected into compromised WordPress sites.

Third, the fake trading page quietly loads a hidden page that checks whether the visitor is using Safari on iOS versions 18.4.0 through 18.7.2. If it finds a match, it launches the exploit chain with no further interaction from the user. Report URI stresses that this is the loader’s target range, not a confirmed exploitable range. It also notes that Google reports two later-stage flaws in the chain were fixed in iOS 18.7.2. The recovered modules include code execution through Safari’s JavaScript engine, a sandbox escape through the GPU process into a media daemon, a kernel exploit, and an implant that takes over securityd to decrypt the keychain.

iVerify describes the P7 changes as deliberate and competent, unlike the many broken, apparently AI-assisted rewrites of the leaked kit it has seen. The variant removes debug logging, injects into fewer processes, uses browser local storage so it does not exploit the same handset twice, and extracts keychain data on the device instead of copying the whole database. The implant sits inside SpringBoard and checks in with its operator for tasks every 15 seconds by default. It can run commands, upload files and collect Notes, photos and wallet data. Report URI’s build contacts a separate server every 30 seconds and targets messages, call history, location history, Health data, saved Wi-Fi passwords and wallet files from more than 25 crypto apps.

Flow diagram of the five stages from a re-registered analytics domain to the DarkSword implant on an iPhone

Why it matters for UK organisations

None of the published research names UK stores or UK victims. Many small and mid-sized British retailers run on hosted platforms or WordPress themes that have built up years of marketing and analytics snippets. Agencies add tags, vendors fold, and nobody removes the script. If the domain behind one of those tags lapses, anyone who registers it gets to run code on your checkout pages, with your customers trusting your brand.

iPhones are common in UK corporate fleets and among staff using their own devices. An unpatched iOS 18 handset that browses a compromised shop at lunchtime could leak its keychain, along with whatever corporate credentials and session data it holds. Censys has separately found open directories tying DarkSword to an exploitation-as-a-service business run by Chinese speakers.

There is a compliance angle too. Version 4.0 of PCI DSS requires merchants to keep an inventory of scripts on payment pages and to detect unauthorised changes. A forgotten tag on a hijacked domain is exactly what those controls should catch.

Expert view

Client-side supply chain risk is usually framed as a trusted vendor being breached. This campaign shows a simpler, cheaper version: the vendor no longer exists, and its domain is available to buy. Registration is cheap, and it buys a foothold on every site that never cleaned up. When we review e-commerce estates, the third-party script list is nearly always longer than anyone expects, and no one can say who owns half of it.

The filtering is the part red teamers should note. Checks on residential IPs, one-shot delivery and crawler cloaking mean a security team scanning its own site from the office or a cloud scanner may see nothing wrong. In my experience, that gap between what defenders test and what real customers receive is where these campaigns survive. On the mobile side, a no-click iOS chain only works against devices behind on updates, so patch latency is the control that counts.

What to do now

  1. Inventory every third-party script on public sites, especially checkout and login pages. Remove anything without a current business owner, and check that each remaining vendor’s domain is still controlled by that vendor.
  2. Search your templates and tag managers for the domains Report URI published, including ecomtrack.io, araleads.com and getmanyme.com, and block the related broker and command-and-control domains at your web proxy.
  3. Enforce a Content Security Policy and use Subresource Integrity where scripts are static, so injected or changed code fails to load or triggers an alert.
  4. Get managed iPhones off iOS 18. Use MDM to set a minimum OS version and block corporate access from out-of-date devices. Under Cyber Essentials, security update management requires high and critical fixes within 14 days, and that includes personally owned devices in scope.
  5. Consider Lockdown Mode for high-risk staff and load iVerify’s indicators into mobile threat defence and DNS filtering.
  6. Test from the customer’s point of view. Check your sites from residential connections and real mobile browsers, not just from datacentre scanners.

Bottom line

P7 DarkSword combines a competently maintained iPhone exploit kit with one of the oldest weaknesses on the web: JavaScript nobody owns any more. UK retailers should treat abandoned tags as live attack surface, and every organisation should check that its iPhones are no longer on the iOS 18 builds this kit targets.

Sources