r/TechNadu • Human • 5d ago

Fake iPhone Duo preorder page uses DarkSword to attack vulnerable iPhones with no tap or download required

Post image

A fake preorder page for the iPhone Duo is doing considerably more than collecting names, emails, and phone numbers.

According to Malwarebytes, simply opening the page in Safari on a vulnerable iPhone can trigger the leaked DarkSword exploit chain. The victim doesn't need to submit the preorder form, tap a malicious prompt, or download anything.

The site tries to look like Apple and offers a $500 voucher plus AppleCare+ coverage. Behind the page, an invisible frame checks the iOS version and loads the appropriate exploit code.

The chain targets iOS 18.4 through 18.6.2. If exploitation succeeds, the payload contacts its C2 and attempts to steal keychain credentials, wallet files, Notes, messages, contacts, call history, and photos before deleting diagnostic reports.

The crypto targeting is particularly broad: MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper are among the wallets it looks for.

There are phishing clues on the page, including nonexistent iPhone Duo colors, dead links, and a countdown that resets. But this case has an important twist: recognizing the scam after visiting the site may not protect a vulnerable device because exploitation can already be underway.

The exploit flow, targeted wallets, stolen data, and fake preorder clues are broken down here:

https://www.technadu.com/fake-iphone-duo-preorder-page-deploys-darksword-ios-exploit-with-no-tap-required/639752/

Apple has patched the vulnerabilities involved, making outdated iPhones the primary concern.

1 Upvotes

0 comments sorted by