
On Thursday, October 1, 2026, Gadgets 360 reported that scammers are using a counterfeit pre-order website for the upcoming iPhone Duo to spread malware aimed at stealing cryptocurrency from visitors’ phones.
The fake site imitates Apple’s legitimate storefront and advertises a $500 discount voucher billed as an “Authorised Partner Exclusive.” The iPhone Duo is scheduled to open for pre-orders on Friday, October 16, but the fraudulent page invites users to reserve a device ahead of that date.
Researchers at Malwarebytes said the site relies on an exploit chain known as DarkSword, which targets iPhones that have not been updated to the latest software. According to the report, victims do not need to click or download anything. Simply loading the page can trigger the attack on a vulnerable device.
Once a phone is compromised, the malware first collects identifying information about the device. It then attempts to transmit a list of installed applications along with the contents of the user’s Apple Notes.
The code then turns to cryptocurrency. It scans for wallet apps including MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus and Tonkeeper, and tries to pull saved credentials from the phone’s keychain. If it finds a wallet of interest and connects to its remote server, it attempts to upload wallet files, the extracted credentials, and thumbnail images. Exposure of such data can put a victim’s funds at risk.
The malware also tries to access messages, contacts, call logs, voicemails, emails, calendar entries, and cached location data. It can additionally contact its controlling server to receive further instructions.
Google reported the DarkSword exploit chain in March, and Apple patched the vulnerabilities the same month. Devices running current software are therefore not exposed to this particular attack.
The report noted that this is not the first time Apple’s ecosystem has been linked to crypto theft. In July, three customers filed a lawsuit in the US District Court for the Northern District of California, claiming they lost about $1.8 million after downloading a fake Bitcoin wallet from Apple’s App Store. The complaint alleges Apple failed to properly vet the apps in question, despite presenting the App Store as a trustworthy source for software.
Source: Gadgets 360





Be the first to comment