Skip to content

A fake iPhone Duo pre-order page runs the DarkSword exploit on unpatched iPhones

Malwarebytes found a fake iPhone Duo pre-order page that tries the leaked DarkSword exploit chain on any iPhone that opens it, before a form is touched.

Pinkesh Gajera5 min read

Security researchers at Malwarebytes have found a fake iPhone Duo pre-order website that tries to break into any vulnerable iPhone that opens it.

In an analysis published on 29 September, Malwarebytes says the page uses the leaked DarkSword exploit chain, and that it starts the attempt as soon as it loads. The visitor does not need to fill in the form, tap a download or approve anything. The page copies Apple's design down to the logo and a copyright footer, and offers what it calls an Authorized Partner Exclusive: a $500 voucher and AppleCare+ cover in return for a name, email address and phone number, with no payment asked for up front. According to Malwarebytes, the form does nothing with what is typed into it. It shows its own success message while the exploit runs in the background.

Apple has not opened pre-orders. MacRumors, reading Apple's iPhone Duo page, reports that customers can use Apple's Get Ready process from 12 October, that pre-orders begin on 16 October at 5am Pacific time, and that the phone launches on 23 October from $1,999. Malwarebytes gives the same pre-order date, and lists other giveaways: the fake page offers the Duo in colours Apple does not sell, its countdown restarts on every load, and its privacy and terms links go nowhere.

None of the tells on the fake page needs technical knowledge to spot. The discount alone should end the visit, because Apple does not discount a phone before it ships.
None of the tells on the fake page needs technical knowledge to spot. The discount alone should end the visit, because Apple does not discount a phone before it ships.

What the page does when it opens

Malwarebytes describes a sequence that matches DarkSword as Google's Threat Intelligence Group documented it in March. A visitor in a browser the script does not recognise as Safari sees a Browser Restricted notice, and on an iPhone the page tries to reopen itself in Safari, which is the browser the chain targets. An invisible frame then checks the iOS version and picks the code to load. If the exploit succeeds, the payload sends a device identifier, the list of installed apps and the contents of Apple Notes to its server, then searches for six named cryptocurrency wallets, among them MetaMask, Phantom and Coinbase Wallet, and tries to recover saved credentials from the keychain. Malwarebytes says it also attempts to reach messages, contacts, call history, voicemail, email, calendar entries and cached location data, and deletes diagnostic reports that could help investigators.

Two limits on the findings matter. Malwarebytes says it analysed the captured code but did not run it on an iPhone or see data leave one. And it found no mechanism that restarts the payload after a reboot.

Which iPhones are at risk?

Phones that have not been updated. Google's disclosure on 18 March said DarkSword supported iOS 18.4 through 18.7, used six vulnerabilities, three of them zero-days, and that all six were fixed with the release of iOS 26.3, most of them earlier. The outlets reporting the fake page give different patch dates, March in one case and April in another; Google's account is the one we rely on. Malwarebytes has not confirmed the exact range this page targets, and says its files also contain code for older versions. It also notes that Safari can report an older iOS version to websites, so an updated iPhone may still download the attack code without the exploit being able to work.

The scale comes from a figure Malwarebytes repeats with a caveat: in March, iVerify estimated up to 270 million devices were running the iOS 18.4 to 18.6.2 versions one DarkSword variant targeted. Malwarebytes is explicit that this is not a current count.

What to do if you opened it

Malwarebytes advises updating through Settings, General, Software Update, turning on Automatic Updates, and restarting the phone after updating. Anyone who keeps a cryptocurrency wallet on a phone that may have been compromised should create a new wallet with a new recovery phrase from a trusted device and move the funds, and change passwords for email, Apple Account, banking and exchanges, starting with those. Google's March advice for a device that cannot be updated is to turn on Lockdown Mode.

Our take

The detail worth dwelling on is the lineage. Google first saw DarkSword in November 2025 in the hands of commercial surveillance vendors and a suspected state-backed group, aimed at targets in Saudi Arabia, Turkey, Malaysia and Ukraine. Ten months later the same chain is sitting behind a consumer scam with a fake voucher. That is the usual life of an iPhone exploit once it leaks, and it is why Apple's patches for attacks it describes as targeted, such as the CoreGraphics flaw fixed in iOS 26.7.1, deserve installing by people who are sure nobody is targeting them. A tool built for a few people tends to reach everyone else in the end.

The lure is chosen with some care. Someone shopping for a $1,999 foldable is, as Malwarebytes points out, quite possibly holding an older phone, and the iOS 18 releases DarkSword targets are exactly where someone who skipped iOS 26 would still be. The fake page also lists the Duo in 6.3 and 6.9 inch sizes, which Apple's own specifications give for the iPhone 18 Pro and Pro Max, a slip that says the operators copied the wrong product page rather than anything about the attack. Among the indicators Malwarebytes published is an ad click and conversion tracker. The firm does not draw the conclusion, but that points to the page being bought into feeds as advertising, not only sent as links.

APPDOOK's reading is that the timing will repeat. The real pre-order window is a fixed, published date, and anything promising earlier access before 16 October is false by definition. Apple published the Duo dates weeks ago, as we noted when we reported that the iPhone Duo arrives on iOS 27.1 on 23 October, which gives scammers a long run-up. What nobody has said is how many people have opened the page, whether any phones have been compromised, or whether Apple has had the domain blocked. Until someone does, the useful advice is the boring one: update the phone, and type apple.com rather than tapping a link.

Sources

  1. Fake iPhone Duo preorder scam triggers DarkSword attackMalwarebytes, 2026-09-29
  2. The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat ActorsGoogle Threat Intelligence Group, 2026-03-18
  3. You Can 'Get Ready' for iPhone Duo Pre-Orders on October 12MacRumors, 2026-09-29
  4. Fake iPhone Duo preorder page can steal crypto wallet data and much more9to5Mac, 2026-09-30
  5. New malware site promises iPhone Duo discounts and early pre-ordersAppleInsider, 2026-09-30
  6. iPhone 18 Pro and iPhone 18 Pro Max - Technical SpecificationsApple, 2026-09-29

Reporting and images linked above belong to their respective publishers and are shown from their own servers. The analysis here is our own.

AppleSecurityiPhone DuoSafariScams

Keep reading