> Fake iPhone Duo preorder scam triggers DarkSword attack
[DATE: 29/09/2026 09:56]
[LANGUAGE: EN]
Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it.
Most of what we found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud.
But one fake preorder page was different.
The fake Apple-style page offers a $500 voucher and a ticking preorder deadline.
Behind its Apple-style design and $500 voucher, the page uses the leaked DarkSword exploit chain to try to break into vulnerable iPhones. If it succeeds, a separate payload attempts to steal saved credentials, cryptocurrency wallet data, and notes.
You don’t have to fill in the form, tap a download, or approve anything. Opening the page is enough to start the attempt.
The $500 voucher is a distraction
The page looks like Apple’s, down to its logo and “Copyright © 2026 Apple Inc.” footer. It promises an “Authorized Partner Exclusive” $500 voucher and AppleCare+ coverage if you complete a preorder form. The form asks for your name, email, and phone number, with WhatsApp “preferred,” but promises no upfront payment.
The form asks for contact details and offers Duo models and colors that do not match Apple’s.
But Apple doesn’t open iPhone Duo preorders until October 16. You cannot place an Apple preorder now. It offers 6.3-inch and 6.9-inch models in colors Apple doesn’t sell for the Duo. Its countdown starts over whenever the page loads, and its privacy, terms, and sales policy links go nowhere.
In the version we captured, submitting the form doesn’t place an order. Its submission handler doesn’t read or send the details entered, and the page generates its own “Pre-Order Successful” message. The exploit attempt has already begun in the background.
How the attack starts when the page opens
Visitors using browsers the script doesn’t recognize as Safari see a “Browser Restricted” notice. On iPhones, the page also tries to reopen the link in Safari, the browser the exploit chain targets. That steers visitors toward the intended browser, although background resources may still load in others.
Visitors shown this notice are urged to open the page in Safari.
An invisible frame checks the visitor’s iOS version and selects the next code to load. DarkSword then attempts to get past the iPhone’s protections and, if successful, gain deep access to the phone. It doesn’t wait for a button press or form submission.
What attackers could take from an iPhone
If the exploit succeeds, the payload attempts to contact its server. Its first message includes a device identifier, device information, and status. It also attempts to send a list of installed apps and the contents of Apple Notes.
The code looks for cryptocurrency wallets, including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper. It also attempts to recover saved credentials from the phone’s keychain. If it finds a targeted wallet and the first exchanges with its server succeed, it attempts to upload wallet files, recovered keychain data, and photo thumbnails. Exposure of wallet files or credentials could put funds at risk.
The captured code checks for installed cryptocurrency wallet apps. This is part of the list.
The payload also tries to access files containing messages, call history, contacts, voicemail, email, calendar entries, and cached location data.
The payload can then repeatedly contact its server for instructions. Its commands can list directories, retrieve files and full-size photos, gather app information, and run JavaScript supplied by the server. The payload also tries to cover its tracks by deleting diagnostic reports that could help investigators spot the attack.
The beacon sends a device identifier, device information and status to the configured server. The command loop uses the response to obtain instructions.
The code is designed to run inside a system process, but may stop before the phone restarts. We found no mechanism that automatically brings it back after a reboot.
We analyzed the captured code, but did not test it on an iPhone or observe data leaving one.
Which iPhones could be at risk?
Several parts of the captured code match the DarkSword chain described by Google in March. Apple has patched the vulnerabilities Google reported.
When DarkSword was disclosed in March, iVerify estimated that up to 270 million devices were running the iOS 18.4 through 18.6.2 versions targeted by the variant it analyzed. That is not a current count or a measure of how many phones this page could compromise. We haven’t confirmed this page’s exact range; its files also contain code for older iOS versions.
The lure fits the exploit: someone considering a new iPhone may still be using an older, unpatched one. That could make them vulnerable simply by opening the preorder page.
Safari can report an older iOS version to websites, so an updated iPhone may still load the attack code. That doesn’t mean the exploit can break in: Apple says updated devices are protected against the reported attacks.
How to stay safe
Keep your iPhone updated. Go to Settings > General > Software Update and install the latest version available. Turn on Automatic Updates there too. Apple says updated devices are protected against the reported DarkSword attacks.
Check offers without opening unfamiliar links. Go directly to Apple or a retailer you know by typing its address yourself. A preorder link in an ad, message, or social post could start an exploit attempt as soon as the page opens.
Opened this page? Restart your iPhone after updating it. We found no code that automatically brings the payload back after a reboot. Restarting cannot undo any data already taken.
Keep a cryptocurrency wallet on that phone? Take precautions from a trusted device. If the phone may have been compromised and you keep a wallet on it, create a new wallet with a new recovery phrase and move the funds. For an exchange account, secure the account and contact the exchange.
Change potentially exposed passwords from a trusted device. Start with email, your Apple Account, banking, and crypto accounts, and turn on two-factor authentication.
Report the page. Save its URL and any screenshots without reopening it, and report it to your national cybercrime reporting service.
Check a suspicious offer before you act. Scam Guard can give a verdict on a screenshot or link. On desktop, Browser Guard blocks the fake preorder page we analyzed; web protection in Malwarebytes Premium blocks it too.
Indicators of compromise
pnmrud[.]cc — command-and-control and collection server
cloud[.]cmatgldn[.]click — ad click and conversion tracker
“One of the best cybersecurity suites on the planet.”
According to CNET. Read their review →