Fake iPhone Duo preorder page tries to hijack iPhones

Published

A fake Apple preorder page for the new foldable iPhone Duo promises a $500 voucher and free AppleCare+, but the form is a decoy. Behind it, the page tries to break into the visitor's iPhone using the leaked DarkSword exploit chain, then steal saved passwords, crypto wallet files and notes. Researchers at Malwarebytes, who documented it in the original report, say the victim does not have to fill in the form, tap a download or approve anything. Opening the page is enough.

Apple announced the iPhone Duo on September 9 and does not open preorders until October 16, so no genuine Duo preorder page exists yet. The fake one copies Apple's branding down to the copyright footer, offers screen sizes and colours Apple does not sell, and runs a countdown that resets every time the page loads. In the version Malwarebytes captured, submitting the form sends nothing anywhere; the page simply prints its own "Pre-Order Successful" message.

The exploit starts before the form does

Visitors on browsers the script does not recognise as Safari see a "Browser Restricted" notice, and on iPhones the page tries to reopen itself in Safari, the browser DarkSword targets. An invisible frame checks the iOS version and picks the code to load next. Malwarebytes says several parts of the captured code match the DarkSword chain Google described in March, and that Apple has already patched the vulnerabilities Google reported. When DarkSword was first disclosed, iVerify estimated up to 270 million devices ran the iOS 18.4 to 18.6.2 versions targeted by the variant it studied; Malwarebytes cautions that this is not a current count and that it has not confirmed the exact version range this page targets.

The lure fits the exploit neatly. Someone shopping for a new iPhone is, quite often, still carrying an old and unpatched one.

What the payload goes after

If the exploit succeeds, a payload beacons to its server with a device identifier and status, then tries to send the list of installed apps and the contents of Apple Notes. It looks for crypto wallets including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus and Tonkeeper, and tries to recover keychain credentials. It also reaches for messages, call history, contacts, voicemail, email, calendar entries and cached location data, and can take further commands to list directories, pull files and full-size photos, and run server-supplied JavaScript. It deletes diagnostic reports to cover its tracks. Malwarebytes found no mechanism that survives a reboot, and notes that it analysed the code without running it on an iPhone or watching data leave one.

That fits a pattern. Last month, Malaysia's MyCERT warned of a cloned parking website that hacked iPhones with no tap, another sign that exploit chains once reserved for targeted spyware are turning up behind ordinary consumer lures.

Update iOS, then restart

Apple says updated devices are protected against the reported DarkSword attacks, so the fix is Settings, General, Software Update, with Automatic Updates switched on. Apple also shipped a separate fix for an exploited CoreGraphics zero-day this week. Anyone who opened the page should update and then restart the phone. If a crypto wallet lived on that device, Malwarebytes advises creating a new wallet with a new recovery phrase from a trusted device and moving the funds, and changing email, Apple Account, banking and exchange passwords with two-factor authentication turned on. Preorder offers are best checked by typing Apple's or a known retailer's address directly rather than following an ad or message.

Indicators published by Malwarebytes:

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions