A fraudulent website claiming to offer early pre-orders for an iPhone Duo is actively deploying the DarkSword exploit chain against vulnerable Apple devices, putting personal information, saved credentials, and cryptocurrency wallet data at risk, Malwarebytes cybersecurity researchers warn.
Fake iPhone Duo Website Offers USD 500 Voucher
Designed to mimic a legitimate Apple portal, the scam site attempts to entice visitors with a USD 500 (approximately Rs. 48,100) discount voucher labeled as an ‘Authorized Partner Exclusive’.
Timing its arrival ahead of official iPhone Duo pre-orders—which are set to kick off on Friday, October 16—the fake website tricks victims into believing they are securing early access.
The page mimics Apple’s design aesthetic, incorporating a pre-order form requesting personal details like a name, phone number, and email address alongside a countdown timer. Yet, closer inspection reveals that the countdown restarts every time the page is refreshed, while links leading to the sales policy, terms, and privacy policy remain entirely non-functional.
DarkSword Attack Can Begin When Page Opens
Beyond the phishing scam, a far more dangerous threat lurks beneath the surface. Malwarebytes discovered that the site deploys the DarkSword exploit chain to target vulnerable iPhones.
Visitors do not have to fill out the pre-order form, download any files, or grant installation permissions for the danger to manifest. Simply navigating to the malicious page is enough to trigger the assault on an unprotected device.
If the exploit succeeds, the malware gathers device identification data, scans for installed applications, and tries to infiltrate data saved within Apple Notes.
The threat actors then focus on popular cryptocurrency wallets, such as MetaMask, Trust Wallet, Phantom, Coinbase Wallet, Tonkeeper, and Exodus, alongside efforts to scrape saved credentials directly from the iPhone’s Keychain.
Also Read: Google Ordered to Shut Hundreds of Firebase Accounts Over Scams
Malware Targets Personal Data
Upon locating a targeted wallet and establishing a successful connection with the operators’ server, the malware moves to upload photo thumbnails, harvested credentials, and wallet files.
Additionally, the payload seeks access to emails, messages, contacts, call logs, calendar entries, cached location data, and voicemails. It also maintains a communication channel with the command server to take in further commands.
The DarkSword exploit chain was initially disclosed by Google in March, prompting Apple to issue patches for the underlying vulnerabilities later that same month.
This campaign underscores the dangers tied to clicking unverified links that advertise premature availability or massive price cuts. Device owners must ensure their iPhones remain updated and confirm all pre-orders exclusively through official Apple channels rather than unknown web addresses.




