Back to feed
CybersecuritySingle source

Fake iPhone Duo preorder page targets crypto wallets with DarkSword exploit

A fake iPhone Duo preorder site can attack some older, unpatched iPhones as soon as the page is opened. Malwarebytes researchers say it uses the DarkSword exploit chain and advertises a $500 voucher to lure visitors.

Preferred on Google
Text size

Brand mark: Apple · Simple IconsSimple Icons CC0 data; trademark used for editorial identification

A scam iPhone Duo preorder page is attempting to steal data from some older iPhones without requiring users to tap a button, download a file or approve a permission. The legitimate preorder period is scheduled to begin Friday, October 16.

The site copies Apple’s design and advertises a $500 voucher presented as an “Authorized Partner Exclusive.” Malwarebytes researchers say the page uses the DarkSword exploit chain.

Data targeted by the payload

After a successful attack, the code collects device identifiers and status, a list of installed apps and the contents of Apple Notes. It then attempts to recover saved credentials from the keychain and search for cryptocurrency wallets.

The targeted wallets include MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus and Tonkeeper. If it finds a wallet and its initial exchanges with the server succeed, the payload attempts to upload wallet files, keychain data and photo thumbnails, potentially putting funds at risk.

The code also tries to access messages, contacts, call history, voicemail, email, calendar entries and cached location data. Its server can provide further instructions.

DarkSword was addressed by updates

Google disclosed the exploit chain in March, and Apple issued a patch later that month. Malwarebytes said the exposure concerns devices that have not installed those updates.

The researchers advise avoiding links from untrusted senders and installing iOS updates as soon as they become available.

What we know

  • The fake iPhone Duo preorder page can start its attack when the page is opened.
  • It advertises a $500 voucher and uses the DarkSword exploit chain.
  • Targets may include MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus and Tonkeeper.
  • Google disclosed DarkSword in March, followed by an Apple patch later that month.

Trust: Single source

  • The story relies on one publisher. A second independent confirmation has not been established from the cited sources.
  • Cited links: 1. Publisher groups: 1. Sources: 9to5Mac.
  • Monitoring in the past hour: 37 of 37 RSS sources; available: 37, unavailable: 0. Matching covers published stories from the past 7 days. This does not cover the entire web.
  • Additional citations require matching headlines, context, event timing and accessible article text. This automatically finds related coverage; it does not establish independence or the truth of every claim.
Related updates appear in the story timeline. This assessment changes with the sources attached to this story.
View sources1

COMMUNITY

Discussion

0

No comments yet. Start the discussion.