
Anthropic Cuts Live Internet Access Over Claude Exploits
Anthropic cuts live internet access for internal evaluations after autonomous Claude agents fell prey to prompt injection flaws and probed live websites.
The stealthy P7 DarkSword iOS exploit kit introduces bidirectional C2 capabilities and targeted cryptocurrency wallet theft across compromised Apple devices.
Senior Technology Analyst

The stealthy P7 DarkSword iOS exploit kit introduces bidirectional C2 capabilities and targeted cryptocurrency wallet theft across compromised Apple devices.
A newly documented strain of the notorious DarkSword framework demonstrates how commercial surveillance software is evolving beyond traditional wiretapping and location telemetry. Dubbed P7 DarkSword by security researchers at mobile defense firm iVerify, this iteration re-engineers the framework's post-exploitation toolkit. By paring back its on-device footprint, establishing persistent two-way command-and-control channels, and targeting mobile cryptocurrency wallets alongside the iOS Keychain, the P7 DarkSword iOS exploit kit marks a calculated shift toward high-value financial theft and real-time remote orchestration.
Commercial iOS exploit kits have historically focused on persistent espionage: exfiltrating encrypted messaging databases, pulling call logs, streaming microphone audio, and cataloging target coordinates for state-aligned operators. The P7 variant breaks with this convention. While it retains the deep surveillance hooks expected of a high-end mobile framework, its underlying architecture now treats decentralized finance assets and application-level credentials as primary collection targets.
The DarkSword family first gained notoriety as a turn-key web-based exploitation chain, frequently distributed via targeted watering-hole attacks and phishing links delivered through SMS or messaging platforms. Early versions relied on multi-stage browser exploitation chains—typically chaining a WebKit remote code execution bug with a sandbox escape and a kernel privilege escalation exploit capable of defeating Apple's Page Protection Layer (PPL) and Pointer Authentication Codes (PAC).
In older iterations, once kernel read-write access was achieved, the implant staged a sprawling suite of monitoring binaries in writable directories, modifying system daemons to ensure survivability across soft reboots. While effective, this heavy footprint left breadcrumbs: anomalous process launches, elevated memory pressure, and anomalous filesystem entries that mobile threat defense agents and endpoint detection scripts could flag.
According to iVerify's technical advisory, P7 fundamentally reconfigures this operational pattern. The developers systematically stripped out legacy surveillance modules that generated persistent disk noise, choosing instead to execute the primary post-exploitation payload entirely in volatile memory. By operating out of memory-mapped allocations injected into existing, legitimate system processes, the P7 DarkSword iOS exploit kit avoids writing secondary utility binaries to the underlying APFS volume, dramatically blunting forensic discovery.
The most consequential departure in P7 is its specialized asset extraction engine. Traditional mercenary spyware treats system credentials as secondary intelligence to support persistent network access. P7, conversely, implements bespoke harvesting routines aimed squarely at decentralized finance platforms and cryptographic key storage.
On modern iOS architectures, security boundaries heavily depend on sandboxing, data protection classes, and the Secure Enclave processor. However, once an attacker achieves arbitrary kernel execution, application sandbox boundaries collapse. The P7 payload abuses this compromised privilege boundary to interface directly with securityd, the system daemon responsible for managing the iOS Keychain.
While hardware-bound cryptographic keys generated within the Secure Enclave remain computationally inaccessible without the underlying hardware coprocessor, most consumer mobile cryptocurrency wallets do not store seed phrases or raw private keys in hardware-backed storage due to cross-platform compatibility and architectural constraints. Instead, wallets such as MetaMask, Trust Wallet, Phantom, and Coinbase Wallet typically secure their encrypted key stores using access control classes like kSecAttrAccessibleAfterFirstUnlock or local SQLite databases encrypted with keys derived from user passcodes.
Because the P7 implant operates while the target device is in an authenticated state—unlocked by the user during the initial phishing interaction—it queries the Keychain API under the identity of the targeted application or dumps the decryption secrets directly from the target process's memory space. P7 incorporates automated scrapers that systematically parse the local sandbox directories of widely used wallet applications, pulling raw database fragments, cached JSON RPC tokens, and unencrypted mnemonic recovery phrases stored in application state snapshots.
Beyond automated financial harvesting, P7 replaces older, one-way beaconing infrastructure with a modular, bidirectional command-and-control (C2) pipeline. Earlier versions of the DarkSword implant relied primarily on scheduled outbound HTTPS exfiltration: gathering a static bundle of device data, encrypting it against an embedded public key, and POSTing it to a remote staging server at fixed intervals.
The bidirectional engine in P7 allows operators to interact dynamically with an infected device in real time. Using lightweight WebSocket connections wrapped in customized TLS profiles designed to mimic background iCloud synchronization traffic, the implant maintains an interactive session with the attacker’s control nodes. This channel permits the remote operator to:
This responsive model grants operators surgical control. If a victim does not possess the high-value cryptocurrency portfolios or specific sensitive credentials the operator seeks, the kit can silently decommission itself, clearing its transient allocations and leaving minimal forensic artifacts behind for mobile incident responders.
The surfacing of P7 highlights the ongoing commodification of advanced iOS offensive capabilities. Exploitation frameworks that once required nation-state budgets are increasingly adopted by financially motivated cybercrime cartels and hybrid mercenary outfits operating across gray markets.
For enterprise defense teams and individual targets, traditional detection paradigms continue to fall short against sophisticated iOS browser-to-kernel chains. Standard Mobile Device Management (MDM) platforms lack real-time introspection into running kernel processes and cannot detect volatile memory injection without triggering invasive privacy violations or violating iOS platform constraints.
Apple's Lockdown Mode remains the most formidable built-in mitigation against the delivery vectors favored by kits like DarkSword. By drastically reducing the WebKit attack surface—disabling just-in-time (JIT) JavaScript compilation, blocking non-standard font formats, and disabling link previews in message payloads—Lockdown Mode neutralizes the initial entry points that exploit kits depend on to gain code execution before privilege escalation can even begin.
For users managing substantial digital assets on mobile hardware, the P7 variant underscores the inherent hazards of relying on software-based key storage on general-purpose computing platforms. When an operating system's kernel is compromised, no software-level sandbox or local application PIN can defend underlying secrets. Until wallet developers mandate hardware-isolated transaction signing through the Secure Enclave or dedicated physical hardware modules, high-tier exploit kits like P7 DarkSword will continue to treat mobile devices not merely as communication channels to tap, but as liquid digital vaults waiting to be drained.
This report was independently synthesized, fact-checked, and expanded with technical mitigation guidance and risk evaluations by the Zero Hour Tech editorial desk. Initial reporting, vendor bulletins, or threat telemetry were tracked from thehackernews.com .
Contributing editor at Zero Hour Tech, specializing in cybersecurity & privacy analysis, vulnerability response, and emerging software paradigms.
View Full Profile & Articles →
Anthropic cuts live internet access for internal evaluations after autonomous Claude agents fell prey to prompt injection flaws and probed live websites.

Enterprises spend millions securing in-house LLMs, but the third-party agent problem leaves over a thousand autonomous SaaS tools invisible to identity stacks.
Get our concise weekly security briefings covering newly disclosed vulnerabilities, exploit mechanics, and actionable system hardening guides.
100% Privacy guaranteed. One-click unsubscribe at any time.