< Back to all clusters
[TECHNOLOGY] · United States · 3 sources

started · updated

iPhone Duo scam uses DarkSword exploit to target users

Cybersecurity experts have identified a sophisticated phishing campaign targeting iPhone users through fraudulent preorder pages for the Apple iPhone Duo. The scam utilizes the leaked DarkSword iOS exploit chain, which allows attackers to compromise a device simply by a user visiting a malicious webpage in Safari, requiring no further interaction or downloads.

The fraudulent site mimics Apple’s official design, offering fake $500 vouchers and AppleCare+ coverage to lure victims into providing personal information. Once a device is compromised, the payload attempts to exfiltrate sensitive data, including keychain credentials, Apple Notes, messages, contacts, call history, photos, and files from various cryptocurrency wallets such as MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper.

Kaspersky has also warned of various fraudulent online stores appearing in multiple languages, including Portuguese, that use visual elements identical to Apple’s official store to promote non-existent offers for new iPhone models. These scams often leverage social media advertisements and deceptive email links to drive traffic to the malicious sites.

Entities

Apple · Darksword · Kaspersky · Malwarebytes · MetaMask · Safari

Claims

What the coverage asserts, and how many sources carry each claim.

  • [○ 1 SOURCE] The malware targets cryptocurrency wallets including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper. www.technadu.com
  • [○ 1 SOURCE] A fraudulent iPhone Duo preorder page uses the DarkSword iOS exploit chain to target iPhones. www.technadu.com
  • [○ 1 SOURCE] Apple is not scheduled to open iPhone Duo preorders until October 16. www.technadu.com
  • [○ 1 SOURCE] The payload attempts to exfiltrate keychain credentials, wallet files, Apple Notes, messages, contacts, call history, and photos. www.technadu.com
  • [○ 1 SOURCE] The exploit requires zero user interaction beyond opening the page in Safari. www.technadu.com
  • [○ 1 SOURCE] Kaspersky identified fraudulent websites advertising non-existent offers for new Apple devices to deceive consumers. www.netthings.pt