A cloned Malaysian parking website is silently breaking into iPhones. Malaysia's national computer emergency response team, MyCERT, says the site parkpeark[.]xyz is an exact copy of the Perak state parking portal Park@Perak, and that simply opening it in Safari on a targeted iPhone is enough to compromise the device. No tap, no login, no download, no permission prompt. MyCERT's advisory MA-1480.082026, published on 29 August, describes the campaign as active.
Zero-click iPhone exploit chains are usually associated with mercenary spyware aimed at a handful of journalists or dissidents. This one sits behind a parking website that any driver in Perak might search for.
A parking page that asks for nothing
The fake site was registered on 25 August 2026. MyCERT found a hidden, zero-size frame injected into the first line of the home page that loads an exploit chain from separate infrastructure. When the chain succeeds it runs the attacker's code inside Safari, escapes the browser's sandbox, raises its privileges to system level and installs a command-and-control implant that keeps running until the phone is restarted.
The site is picky about whom it attacks. Malicious code is served only to iPhone users on Safari; visitors on Android, Windows or an unrecognised browser get a blank page. MyCERT says this is deliberate: researchers and scanners see nothing harmful.
Which iPhones the chain is built for
The recovered chain carries data for the iPhone XS, iPhone 11 Pro, and iPhone 12 and 12 Pro, targeting iOS builds 22E240, 22E252, 22F76, 22G86, 22G90 and 22G100, which MyCERT says correspond to iOS 18.4 through 18.6.x. A separate, older chain is served to devices running iOS below version 18. Phones on current software fall outside that list, one more reason to install Apple's recent fixes for older iPhones.
What the implant takes
MyCERT's list of what a compromised device gives up is long: the SMS database, Notes, Mail, voicemail, call history and address book; the camera roll and full photo library database; saved passwords and tokens from the iOS Keychain plus data from third-party app containers; and location caches, calendar, health data and device activity records. The implant searches specifically for cryptocurrency wallet apps and tries to extract seed phrases and recovery mnemonics. Operators also get a remote channel to run commands, move files and inspect memory.
MyCERT's assessment is that the real danger is how invisible all of this is. There is no app icon, no configuration profile and no certificate prompt. A victim may open the page, find no parking record, close it and never connect a later loss to that visit. The usual advice, do not enter your password and do not install unknown apps, offers no protection here.
Restart the phone, then change every password
For individuals, MyCERT's guidance is to reach government services only by typing the official address (the real portal is park.perak.my) or through an official app, never via links in SMS, WhatsApp, social media or search ads; to keep iOS updated; and, if the site was opened on an iPhone, to restart the device immediately, since the implant does not survive a reboot, then change email, banking and social media passwords from a separate trusted device and move any cryptocurrency to a newly generated wallet.
Organisations are told to block every domain in the advisory at DNS, proxy and mobile device management level, because the later-tier hosts are reachable directly; to review thirty days of DNS and proxy logs for hits; to enforce current iOS versions on managed devices; and to consider Lockdown Mode for staff in high-risk roles. Apple now surfaces spyware warnings on the Lock Screen. MyCERT does not attribute the campaign to any group. It is a reminder that Malaysia remains a heavily targeted market for criminal and espionage operations.
Indicators of compromise
Network: parkpeark[.]xyz (lure site), gk9p1becso5e.2ws3ed4rf5tgy[.]com (second-tier redirector and device fingerprinting), yiivx3sf43zz.6tq8rw2yu4iop[.]com (third-tier redirector), xinyea[.]cc (exploit hosting), hudiea[.]cc (command and control, /beacon and /result), and suk.hypepressobot[.]com (a chat widget on the lure page that MyCERT has not assessed and treats as suspect). On-device artefacts include /tmp/pe_worker_trace.log, /var/mobile/Media/PostLogs.txt, /var/mobile/Media/RemoteLog.log and /var/mobile/ios_disk_scan.txt. Selected SHA-256 hashes: implant 8f7f3d2e6e36445218c6a8daa97219a2ce87661a7b4f1beb6458f0418831cb66; sandbox escape stage cd9d756ac095d02c8876e40a0035397092e796a001b3107da63aecd8b0d3bb85; exploit loader e9a8947610f05bc6add2aed09ed95c5d99488be5c479b7e2dd16f30130b07e0d. MyCERT lists twelve in full.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.