VYPR
breachPublished Sep 29, 2026· 1 source

Fake iPhone Preorder Site Exploits DarkSword Chain for Credential Theft

A sophisticated phishing campaign uses a fake iPhone preorder website to exploit vulnerable iPhones with the DarkSword chain, stealing credentials and cryptocurrency data.

Scammers have launched a sophisticated attack leveraging the recent announcement of Apple's foldable iPhone Duo, creating a fake preorder website designed to exploit vulnerable iPhones simply by visiting the page. The site, mimicking Apple's official design with logos and copyright notices, entices users with a $500 voucher and AppleCare+ coverage, but its primary function is to deploy the DarkSword exploit chain.

The attack bypasses traditional user interaction, meaning no downloads, clicks, or form submissions are required for the exploit attempt to begin. Visitors are presented with a countdown timer and a preorder form that asks for contact details, but the form submission is a ruse. The page's true malicious intent is revealed when it attempts to exploit the iPhone's operating system in the background. A "Browser Restricted" notice may appear, urging users to open the page in Safari, which is the targeted browser for the exploit.

Once the DarkSword exploit chain is successfully deployed, it aims to gain deep access to the iPhone. The payload then contacts a command-and-control server, sending device identifiers, system information, and a list of installed applications. Crucially, it targets sensitive data including saved credentials from the iPhone's keychain and data from popular cryptocurrency wallets such as MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper.

Beyond credentials and cryptocurrency data, the malware payload is designed to exfiltrate messages, call history, contacts, voicemail, email, calendar entries, and cached location data. It also attempts to cover its tracks by deleting diagnostic reports that could alert investigators to the compromise. The malware operates within a system process, but researchers noted no mechanism for automatic persistence after a phone reboot.

The exploit chain used in this attack shares similarities with the DarkSword variant disclosed by Google in March. While Apple has since patched the vulnerabilities reported by Google, the attackers may be targeting older, unpatched iOS versions. Even updated iPhones could potentially load attack code if they are running older iOS versions that report themselves inaccurately to websites, though Apple states updated devices are protected against these specific exploits.

To mitigate this threat, users are strongly advised to keep their iPhones updated to the latest software version via Settings > General > Software Update and enable Automatic Updates. It is also crucial to be wary of unsolicited links, especially for preorders or deals, and to navigate directly to official vendor websites by typing the URL manually.

If a user suspects they may have visited the malicious page, a phone restart is recommended as a precautionary measure, as the payload lacks automatic persistence. For users who store cryptocurrency wallets or sensitive financial information on their devices, it is imperative to create a new wallet with a fresh recovery phrase on a trusted device and transfer existing funds. For exchange accounts, securing the account and contacting the exchange directly is advised.

Synthesized by Vypr AI