Fake iPhone Duo preorder scam triggers DarkSword attack
Cybersecurity Classified by Officially
Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it.
Most of what we found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud.
But one fake preorder page was different.
Behind its Apple-style design and $500 voucher, the page uses the leaked DarkSword exploit chain to try to break into vulnerable iPhones. If it succeeds, a separate payload attempts to steal saved credentials, cryptocurrency wallet data, and notes.
You don’t have to fill in the form, tap a download, or approve anything. Opening the page is enough to start the attempt.
The page looks like Apple’s, down to its logo and “Copyright © 2026 Apple Inc.” footer. It promises an “Authorized Partner Exclusive” $500 voucher and AppleCare+ coverage if you complete a preorder form. The form asks for your name, email, and phone number, with WhatsApp “preferred,” but promises no upfront payment.
But Apple doesn’t open iPhone Duo preorders until October 16. You cannot place an Apple preorder now. It offers 6.3-inch and 6.9-inch models in colors Apple doesn’t sell for the Duo. Its countdown starts over whenever the page loads, and its privacy, terms, and sales policy links go nowhere.
In the version we captured, submitting the form doesn’t place an order. Its submission handler doesn’t read or send the details entered, and the page generates its own “Pre-Order Successful” message. The exploit attempt has already begun in the background.
How the attack starts when the page opens
Visitors using browsers the script doesn’t recognize as Safari see a “Browser Restricted” notice. On iPhones, the page also tries to reopen the link in Safari, the browser the exploit chain targets. That steers visitors toward the intended browser, although background resources may still load in others.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-iphone-duo-preorder-scam-triggers-darksword-attack
Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Malwarebytes — imported from official source
- Official source
- https://www.malwarebytes.com/blog/feed/index.xml RSS
- Imported
- September 29, 2026 11:00
- Versions
- 1 recorded
- Identity
https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-iphone-duo-preorder-scam-tr...