Cybersecurity researchers have warned about a fraudulent iPhone Duo pre-order website that allegedly uses the DarkSword exploit chain to target vulnerable iPhones and steal sensitive information, including cryptocurrency wallet data. The scam site reportedly resembles the legitimate pre-order page and attempts to attract visitors with a $500 discount voucher described as an “Authorised Partner Exclusive.” The iPhone Duo is scheduled to become available for pre-orders on October 16, giving scammers an opportunity to exploit consumer interest ahead of the launch.
According to cybersecurity firm Malwarebytes, the malicious webpage uses the DarkSword exploit chain, which targets certain iPhones that have not been updated with the relevant security fixes. The attack can reportedly begin simply when a vulnerable device opens the malicious webpage, without requiring the victim to download an application or approve a transaction. Once successful, the malware can collect device identification information, examine installed applications and attempt to access content stored in Apple Notes.
The malware then reportedly focuses on cryptocurrency wallets and related credentials. Security researchers said it searches for information associated with wallets including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus and Tonkeeper, while also attempting to extract credentials stored in the device's keychain. If it establishes communication with its server, the malware can attempt to upload wallet files, credentials and thumbnail images, potentially putting cryptocurrency holdings at risk.
Also Read: Vivo V80: 144Hz OLED, 7,200mAh Battery, Zeiss Cameras
The reported payload can also attempt to access other sensitive information, including messages, contacts, call logs, voicemails, emails, calendar appointments and cached location data. Researchers said the malware can communicate with its server to receive additional instructions. The DarkSword exploit chain was reported by Google in March and Apple subsequently released security updates addressing the vulnerabilities, highlighting the importance of keeping compatible devices updated.
The incident follows other cases involving fraudulent cryptocurrency applications and Apple's ecosystem. In July, three customers filed a lawsuit in the US District Court for the Northern District of California alleging that they lost about $1.8 million after downloading a fake Bitcoin wallet from Apple's App Store. The complaint alleged that Apple failed to identify the applications despite its claims about the security and reliability of the App Store. The allegations are part of ongoing legal proceedings and have not been established as findings against Apple.
The latest scam highlights how cryptocurrency users can be targeted without directly installing a fraudulent wallet application or authorising a transaction. Although the vulnerabilities associated with the DarkSword exploit chain have been addressed through Apple's security updates, users with unpatched devices may remain exposed to malicious webpages exploiting older flaws. Security experts advise users to install available device updates and avoid suspicious links offering unusually large discounts, particularly those connected to pre-orders or cryptocurrency services.
Also Read: iQOO 16 Launched With Snapdragon 8 Elite Extreme Gen 6 and 8,400mAh Battery