A fake iPhone Duo pre-order website is targeting vulnerable iPhones with the DarkSword exploit chain, potentially exposing cryptocurrency wallet data, saved credentials, and personal information, according to cybersecurity researchers at Malwarebytes.
The fraudulent website resembles an official Apple page and tries to lure users with a USD 500 (roughly Rs. 48,100) discount voucher described as an ‘Authorized Partner Exclusive’.
The scam comes ahead of the official iPhone Duo pre-orders, which are scheduled to begin on Friday, October 16. The fake website attempts to convince users that they can place their pre-order early.
The page uses Apple-style branding, a countdown timer, and a pre-order form asking for details such as name, email address, and phone number. However, the countdown resets whenever the page loads, and links to its privacy policy, terms, and sales policy do not work.
The more serious threat is hidden behind the fake offer. Malwarebytes found that the website uses the DarkSword exploit chain against vulnerable iPhones.
Users do not necessarily need to download a file, submit the pre-order form, or approve an installation. Simply opening the malicious webpage can begin the attack on an affected device.
If successful, the malware can collect device identification information, check installed applications, and attempt to access content stored in Apple Notes.
The attack then targets cryptocurrency wallets, including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper. It also attempts to extract saved credentials from the iPhone's Keychain.
Also Read: Google Ordered to Shut Hundreds of Firebase Accounts Over Scams
Once it identifies a targeted wallet and successfully communicates with the attackers' server, the malware attempts to upload wallet files, extracted credentials, and photo thumbnails.
The payload can also attempt to access messages, contacts, call logs, voicemails, emails, calendar appointments, and cached location data. It can communicate with its server to receive additional instructions.
Google reported the DarkSword exploit chain in March, and Apple patched the vulnerabilities later that month.
The incident highlights the risks of opening unfamiliar links promising early access or unusually large discounts. Users should keep their iPhones updated and verify pre-order offers through official Apple channels, not unfamiliar websites.