AI News Feed
Market watch
Cybersecurity

Fake iPhone Duo Preorder Page Uses DarkSword Exploit to Steal Crypto Wallet Data

Malwarebytes says a fake iPhone Duo preorder page uses the DarkSword exploit chain to steal crypto wallet data, credentials and notes from older unpatched iPhones.

The page convincingly copies the look of the real product page and claims to offer a $500 discount voucher as an Authorized Partner Exclusive, 9to5Mac reported. Malwarebytes said the page uses the leaked DarkSword exploit chain, which works against some older iPhones that have not been patched. Visiting the page is enough to start the attack; users do not need to fill out a form, tap a download or approve anything.

If the exploit succeeds, a separate payload captures the device identifier and status and attempts to send a list of installed apps and the contents of Apple Notes, according to Malwarebytes. It then looks for cryptocurrency wallets, including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus and Tonkeeper. It also tries to recover saved credentials from the phone's keychain. If it finds a targeted wallet and the first exchanges with its server succeed, it attempts to upload wallet files, recovered keychain data and photo thumbnails. Exposure of wallet files or credentials could put funds at risk.

The payload also tries to access messages, contacts, call history, voicemail, email, calendar entries and cached location data, 9to5Mac reported. It can contact its server for further instructions. Google disclosed the exploit chain in March, and Apple issued a patch later that month.

9to5Mac advised users not to visit links unless they trust the sender and are specifically expecting them, and to install iOS updates as soon as they are available.