iPhone Duo Preorder Trap Starts a DarkSword Attack Before You Submit

Daniel Zimmermann
4 Min Read
Folding phone becomes a trap around a shopping voucher: fake preorder, real attack.
A fake preorder can conceal an attack on an unpatched phone.

A fake iPhone Duo preorder page promises a $500 voucher, but the dangerous part starts before the visitor submits anything. Malwarebytes researchers reported on September 29 that the page loads a DarkSword exploit chain against vulnerable iPhones in the background. Their analysis describes an attempted infection, not a confirmed count of compromised phones.[1]

The preorder is a distraction

The captured site copies Apple’s visual identity and offers a discount without an upfront payment. Its countdown resets when the page reloads. More revealingly, the inspected form does not send the entered contact details: it displays a locally generated success message. The apparent transaction keeps attention on a shopping decision while a hidden frame selects attack code using the visitor’s iOS version.

Captured fake iPhone Duo page showing a 500-dollar voucher and preorder countdown.
The captured fake page imitates Apple and advertises a $500 voucher. Source: Malwarebytes Threat Intelligence.

There is also a date check that does not require visiting the offer. Apple’s own announcement says iPhone Duo preorders begin on October 16. A page offering an Apple preorder on September 29 is ahead of that official schedule.[2] Verify availability by opening Apple’s site independently; a familiar logo on an unfamiliar address is not authorization to sell the phone.

Loading code is different from compromising the phone

The researchers found code aimed at credentials, wallet data and notes, but did not test the captured chain on an iPhone or observe data leaving one. They could not establish this page’s exact vulnerable-version range. A page load can therefore start an attempt; it does not establish that every visitor was infected.

That distinction matters because browser identification is imperfect. The report notes that Safari can advertise an older iOS version even on an updated device. Downloading exploit resources alone is not evidence that the exploit defeated the phone’s protections. Likewise, the lack of a payment or download prompt is not a useful safety test for a web exploit.

Check the installed update, not the offer’s reassurance

Apple’s guidance on the reported web attacks says devices with updated software are protected, including the latest updated releases for supported older iOS branches. Its advice is to install the newest compatible update; a major version number alone is not enough to tell whether an older branch has its security fixes.[3] Open Settings → General → Software Update directly and install the update offered for your device.

If you already opened the fake offer, close it and avoid returning to investigate. Keep the URL from browser history if you need to report it. If account activity suggests theft, handle that separately from updating the phone: secure the affected accounts from a trusted device. Our Apple Account recovery guide explains the account checks. Installing a patch cannot retrieve information already taken.

The useful lesson is specific: on an unpatched phone, deciding not to complete a suspicious order may come too late to prevent the exploit attempt. Check the update and reach the retailer independently before opening an unfamiliar promotion.

References

  1. Stefan Dasic. “Fake iPhone Duo preorder scam triggers DarkSword attack.” Malwarebytes Threat Intelligence, September 29, 2026. Research report.
  2. Apple. “Apple unveils iPhone Duo.” Apple Newsroom, September 9, 2026. Announcement and preorder schedule.
  3. Apple. “Update iOS to protect your iPhone from web attacks.” Apple Support, April 14, 2026; accessed September 29, 2026. Security update guidance.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?