HomeSecurityiPhone Duo: Fake pre-order page hides DarkSword attack

iPhone Duo: Fake pre-order page hides DarkSword attack

A new cybercriminal campaign is attempting to capitalize on the excitement surrounding the upcoming iPhone Duoby using a fake pre-order website to infect vulnerable Apple devices. The page mimics the appearance of an official store and promises a $500 discount, in an attempt to convince visitors to trust it.

iPhone Duo: Fake pre-order page hides DarkSword attack

However, behind the supposed offer lies a much more dangerous activity. According to researchers at cybersecurity firm Malwarebytes, the site leverages the DarkSword exploit chain, which can be used to compromise certain older iPhones that haven't been updated with the necessary security patches.

The particularly worrying element is that, under the right circumstances, the attack can be initiated simply by visiting the malicious page, without the user having to download any file or execute any command.

$500 discount as bait

Pre-orders for the iPhone Duo are scheduled to begin on Friday, October 16.Cybercriminals are attempting to capitalize on the interest surrounding the device by creating a website that presents itself as an authorized Apple partner.

The page advertises a $500 coupon, which appears as an exclusive offer for those who want to secure the new device early. The promise of a big discount acts as a lure, encouraging visitors to open the link without carefully examining its credibility.

See also: Gurman: 'iPhone Duo Max' with larger screen may be released

Using design elements reminiscent of the Apple environment can make the scam harder to recognize, especially on mobile screens where the full address of a website is not always immediately visible.

It’s a familiar social engineering tactic: attackers exploit the excitement about a popular product and consumers’ desire to secure a bargain. In this case, however, the risk is not limited to losing money or having payment details stolen. Visiting the website can be the starting point for an attack against the device itself.

DarkSword exploits iPhone vulnerabilities

According to Malwarebytes, the website uses DarkSword, an exploit chain that can allow malicious code to be executed on devices affected by the specific vulnerabilities.

An exploit chain is not necessarily based on a single flaw. Instead, it combines vulnerabilities or techniques in succession to achieve the ultimate goal of the attack. Depending on its capabilities, it can allow the bypass of security mechanisms and access to data normally protected by the operating system.

In this case, the attack targets some older iPhones that do not have the relevant security updates. This means that not all Apple devices visiting the website are necessarily at risk. The success of the attack depends, among other things, on the version of the operating system and whether the corresponding vulnerabilities remain unresolved.

The critical point is that the user does not have to fill out the pre-order form, click a download button, or approve an obvious installation. As long as the device is vulnerable and the exploit chain works, the process can begin upon visiting the page.

What data does the malware attempt to steal?

If the breach is successfully completed, the malicious payload attempts to collect information about the device and identify data that may be of particular value to the attackers.

Among other things, it searches for information about the iPhone's status, installed apps, and the content of the Apple Notes app. Notes can include personal information, business data, reminders, or even login credentials that the user has stored in an insecure manner.

iPhone Duo: Fake pre-order page hides DarkSword attack

Of particular interest is the targeting of cryptocurrency wallets. The code searches for applications such as MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper, attempting to locate relevant data.

At the same time, it attempts to retrieve stored credentials from Apple's Keychain, the mechanism used to securely store sensitive information. Once data of interest to the attackers is identified and communication with their remote server is established, it can attempt to send wallet files, Keychain information, and photo thumbnails.

Exposing such data can have serious consequences. Especially in the case of cryptocurrencies, the leakage of sensitive information may facilitate the theft of digital assets, depending on the type of data obtained by attackers.

The attack can extend to personal information

The malicious payload's capabilities are not limited to cryptocurrencies. According to campaign information, it also attempts to access communications and other personal data, such as messages, contacts, call history, voicemail, emails, calendar entries, and stored location information.

Gathering this information can provide cybercriminals with a detailed picture of the victim's daily life. The data could be used in subsequent phishing attacks, attempts to scam the victim's contacts, or blackmail, if it includes sensitive material.

Additionally, the malware can communicate with its control server to receive further instructions. This creates the possibility of adapting its activity depending on the data already collected or the commands sent by its operators.

See also: iPhone Duo production problems before launch

This does not mean, however, that all of the above data is intercepted on every infected device. The extent of collection depends on the capabilities the malware manages to acquire and the operating conditions of the attack.

The DarkSword revelation and Apple's fixes

The DarkSword exploit chain was disclosed by Google last March, according to the information accompanying the case. Apple released a related patch later that month to address the vulnerabilities.

This development highlights the importance of installing updates, even when users do not notice a problem with their device. Vulnerabilities can remain invisible during everyday use, while their exploitation can be carried out through websites that seem completely ordinary.

Users should check to see if their iPhone has the latest iOS version supported by their device and install all available security updates. Those using older models should not assume that the lack of new features means that updates are not needed.

iPhone Duo: Fake pre-order page hides DarkSword attack

How to protect yourself from fake pre-orders

The first line of defense is to avoid suspicious links that promise unusually deep discounts or exclusive access to new products. Consumers should confirm offers through official Apple channels and carefully check the domain name before visiting a purchase page.

See also: iPhone Duo: App turns it into a virtual Sony Walkman

At the same time, it is important to keep the operating system updated, avoid storing sensitive information in simple notes , and use available security features to protect accounts and digital wallets.

This campaign demonstrates that a seemingly innocent offer can hide a complex attack. In some cases, user vigilance and timely installation of security updates are decisive factors in preventing a breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS