Stay Far Away from This Fake $500 iPhone Duo Pre-Order Page

Simply visiting this scam site can trigger the DarkSword malware on unpatched iPhones
iPhone Duo Scam Malware DarkSword page
Text Size
- +

Toggle Dark Mode

Apple’s long-awaited iPhone Duo is slated to go up for pre-order on October 16 at 5:00 am PT — and not one second before that — which means you should be very wary of any links claiming to give you early access.

While Apple will let folks get ready on October 12 by effectively loading up their shopping cart, you won’t actually be able to hit the “Buy” button until pre-orders open later that week.

This Limited-Time Microsoft Office Deal Gets You Lifetime Access for Just $39

Sick and tired of subscriptions? Get a lifetime license for Microsoft Office Home and Business 2021 at a great price!

It should also go without saying that Apple isn’t about to start offering deep discounts or other coupons on its shiny new foldable flagship. The company has never offered special launch pricing in the history of the iPhone, and it’s certainly not about to start doing so with the $2,000 iPhone Duo.

Sadly, that hasn’t stopped scammers from trying to profit on the hype. There have been dozens of the usual phishing attempts — sites that simply attempt to steal your information — but the folks at Malwarebytes have found one that’s far more sinister.

A new website has popped up that looks suspiciously like it was designed by Apple, promising an “Apple Partner Exclusive” $500 voucher if users act fast. That alone should be a massive red flag for any Apple fan — Apple just significantly hiked all of its prices, so it’s not about start giving out 25% discounts on a new iPhone model that it probably won’t even be able to manufacture fast enough to keep up with demand.

However, this isn’t just your average everyday trap — it’s a page laden with malware. In fact, the promised discount is just a red herring; the scammer doesn’t care if you click a single thing — simply visiting the page is enough to deliver DarkSword to older, unpatched iPhone models.

Behind its Apple-style design and $500 voucher, the page uses the leaked DarkSword exploit chain to try to break into vulnerable iPhones. If it succeeds, a separate payload attempts to steal saved credentials, cryptocurrency wallet data, and notes.

Malwarebytes

The good news is that this isn’t exactly a bleeding-edge vulnerability. You’ll be safe as long as you’re running a reasonably recent version of iOS — that’s iOS 27, iOS 26.4, iOS 18.7.7, iOS 16.7.15, or iOS 15.8.7. However, it’s worth mentioning here that Apple hasn’t released patches for iOS 13 or iOS 14, as every device capable of running those versions can be updated to at least iOS 15.8.7 for full protection. Equivalent iPadOS versions are also patched against the DarkSword exploit kit.

Still, it’s better to play it safe. Just because your iPhone or iPad is immune to DarkSword, that doesn’t mean you should be visiting a website that exists for no other purpose than to hack your device.

This also goes to show how insidious many of these modern exploits are. While many people will realize this deal sounds too good to be true, this one doesn’t even require a lot of curiosity to spring its trap. That’s because it doesn’t have to persuade anybody to fill in a form or even click a link; again, simply visiting the page is enough to infect an unpatched iPhone or iPad.

For obvious reasons, nobody is about to link to the actual site, but the folks at Malwarebytes have done an analysis as to precisely what the bad actors are looking for. Right off the bat, the exploit will send a list of all the apps you have installed and everything you have stored in Apple Notes. Then it goes hunting for cryptocurrency wallets, messages, call history, contacts, voicemail, email, calendar entries, and cached location data.

All of this without requiring you to do anything more than visit a compromised webpage.

Needless to say, if there was ever a case to be made for ensuring you’re always running the latest iOS patches on your iPhone, this is it. Stubbornly staying behind on ancient versions because you’re afraid of things breaking is guaranteed to leave you in a far more dangerous place than the possibility of encountering a few small software bugs.

Sponsored
Social Sharing