A fake iPhone Duo pre-order website is being used to target vulnerable iPhones with the DarkSword exploit chain, according to security researchers. The scam site imitates an Apple-style pre-order page and reportedly offers a $500 voucher to make the offer appear legitimate.
The timing is designed to exploit interest in Apple’s first foldable iPhone. Apple has confirmed that iPhone Duo pre-orders will begin on October 16, with sales starting October 23 in India and several other markets.
According to Malwarebytes, simply opening the malicious webpage on an unpatched vulnerable iPhone can trigger the attack without requiring the user to install an app or download a file. The exploit can collect device information and inspect installed applications and Apple Notes content.
The attack also focuses on cryptocurrency users. Security researchers said the malware searches for information associated with wallets including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus and Tonkeeper. It can also attempt to access credentials stored in the device keychain.
Apple has previously released security updates addressing vulnerabilities associated with DarkSword attacks. Its security documentation says protections against DarkSword web attacks were included in updates made available for supported devices.
Users should avoid unofficial iPhone Duo pre-order websites, particularly those promising unusually large discounts or vouchers. Pre-orders should be made through Apple’s official website or authorised retail channels.
Technology
Fake iPhone Duo Site Targets Crypto Wallets With Malware
A fake iPhone Duo pre-order website is being used to deliver DarkSword malware, putting crypto wallets and sensitive iPhone data at risk.


