Fake iPhone Duo preorder page targets crypto wallets with DarkSword exploit
A fake iPhone Duo preorder site can attack some older, unpatched iPhones as soon as the page is opened. Malwarebytes researchers say it uses the DarkSword exploit chain and advertises a $500 voucher to lure visitors.
A scam iPhone Duo preorder page is attempting to steal data from some older iPhones without requiring users to tap a button, download a file or approve a permission. The legitimate preorder period is scheduled to begin Friday, October 16.
The site copies Apple’s design and advertises a $500 voucher presented as an “Authorized Partner Exclusive.” Malwarebytes researchers say the page uses the DarkSword exploit chain.
Data targeted by the payload
After a successful attack, the code collects device identifiers and status, a list of installed apps and the contents of Apple Notes. It then attempts to recover saved credentials from the keychain and search for cryptocurrency wallets.
The targeted wallets include MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus and Tonkeeper. If it finds a wallet and its initial exchanges with the server succeed, the payload attempts to upload wallet files, keychain data and photo thumbnails, potentially putting funds at risk.
The code also tries to access messages, contacts, call history, voicemail, email, calendar entries and cached location data. Its server can provide further instructions.
DarkSword was addressed by updates
Google disclosed the exploit chain in March, and Apple issued a patch later that month. Malwarebytes said the exposure concerns devices that have not installed those updates.
The researchers advise avoiding links from untrusted senders and installing iOS updates as soon as they become available.
What we know
- The fake iPhone Duo preorder page can start its attack when the page is opened.
- It advertises a $500 voucher and uses the DarkSword exploit chain.
- Targets may include MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus and Tonkeeper.
- Google disclosed DarkSword in March, followed by an Apple patch later that month.
Trust: Single source
- The story relies on one publisher. A second independent confirmation has not been established from the cited sources.
- Cited links: 1. Publisher groups: 1. Sources: 9to5Mac.
- Monitoring in the past hour: 37 of 37 RSS sources; available: 37, unavailable: 0. Matching covers published stories from the past 7 days. This does not cover the entire web.
- Additional citations require matching headlines, context, event timing and accessible article text. This automatically finds related coverage; it does not establish independence or the truth of every claim.
View sources1
COMMUNITY
Discussion
Sign in to join the discussion.
No comments yet. Start the discussion.