Topics / topic

Malware

1 item across 1 edition. First seen Sun 11 Oct, last seen Sun 11 Oct.

Sunday, 11 October 2026

iVerify says likely LLM-assisted attempts to port the leaked DarkSword iOS spyware kit to iOS 26 keep failing mixedSingle source

  • The Hacker News reports that as of last month iVerify observed "multiple unsuccessful, likely LLM-assisted attempts to update the framework to support iOS 26.x" after the DarkSword kit leaked, and quotes iVerify saying: "Many bundled variants we see are non-working AI slop attempts. Non-sophisticated attackers are deploying broken/non-working versions of patched Coruna and DarkSword from GitHub." iVerify adds it "can't rule out" attackers reverse-engineering and re-implementing Coruna with the help of large language models, but "we just don't have evidence of this happening yet".
  • iVerify's own October 8 write-up of the new variant it calls P7 DarkSword draws the same distinction from the other direction: "unlike many of the AI-assisted variants we observe, the P7 authors understood the code they were modifying: their changes reduced the implant's footprint while extending its theft capabilities". iVerify says P7 "adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker's infrastructure"; The Hacker News reports the implant polls for commands every 15 seconds.
  • The background, per The Hacker News: DarkSword was first documented in March 2026 by Google Threat Intelligence Group, iVerify and Lookout, targets iOS 18.4 through 18.7, and was detected in the wild in November 2025. It has been used against targets in Saudi Arabia, Turkey, Malaysia and Ukraine by actors including the Turkish commercial surveillance vendor PARS Defense and the Russia-aligned Star Blizzard, also tracked as COLDRIVER.
  • This is a vendor's qualitative judgement about code it has seen, not a measured success rate: iVerify gives no count of AI-assisted variants, no attribution for them and no evidence that any model was involved beyond the state of the code. The in-window reporting is The Hacker News alone; iVerify's underlying post predates the window.