{"id":421630,"date":"2026-10-02T06:06:18","date_gmt":"2026-10-02T06:06:18","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=421630"},"modified":"2026-10-02T06:06:18","modified_gmt":"2026-10-02T06:06:18","slug":"fake-iphone-duo-preorder-darksword-attack","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fake-iphone-duo-preorder-darksword-attack\/","title":{"rendered":"Fake iPhone Duo Preorder Scam Exposed: $500 Voucher Hides DarkSword Attack"},"content":{"rendered":"<p>A $500 preorder voucher sounds tempting when a new phone has barely been announced. The page looks familiar enough to invite a quick glance.<\/p><div id=\"mwtad4238194713\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Before you decide whether that offer deserves your details, notice what happens before the form is even finished.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1672\" height=\"941\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Illustrative counterfeit foldable iPhone preorder webpage offering a $500 voucher\" class=\"wp-image-421631 lazyload\" title=\"\" sizes=\"auto, (max-width: 1672px) 100vw, 1672px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-hero-v3.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-hero-v3.png 1672w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-hero-v3-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-hero-v3-1024x576.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-hero-v3-1536x864.png 1536w\"><\/figure>\n<div id=\"mwtad512905151\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The offer in front of the visitor<\/h3>\n<p>A counterfeit iPhone Duo preorder page copied Apple&#8217;s visual language and promised a $500 voucher to people who joined early.<\/p><div id=\"mwtad1353175086\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>It presented the choice as a reservation, not a high-risk security decision. A countdown and Apple-like navigation made the offer feel temporary and official.<\/p>\n<p>The page also asked for contact details, including a phone number. That looked like the obvious reason for the visit.<\/p>\n<p>Yet the visible form was not the most important part of the page. A separate process attempted to run as soon as the page opened.<\/p><div id=\"mwtad440149601\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>What researchers actually observed<\/h3>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/threat-intel\/2026\/09\/fake-iphone-duo-preorder-scam-triggers-darksword-attack\" target=\"_blank\" rel=\"noopener\">Malwarebytes researchers analyzed<\/a> a fake preorder site carrying code associated with the DarkSword iPhone exploit chain.<\/p>\n<p>The researchers found an attempt to reach into vulnerable phones and access valuable data. They did not observe a completed theft from a live device.<\/p>\n<p>That distinction matters. The site was dangerous by design, but opening it does not prove that every visitor&#8217;s phone was compromised.<\/p><div id=\"mwtad3818293601\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<ul>\n<li>The lure was an Apple-style preorder and a $500 voucher.<\/li>\n<li>The risk began when a vulnerable browser loaded the page, before any form submission.<\/li>\n<li>The code attempted access to credentials, wallet information, notes, and other private data.<\/li>\n<li>Current software updates are an important protection against the reported exploit chain.<\/li>\n<\/ul>\n<h3>Why the real company is not behind it<\/h3>\n<p>A copied logo, polished device render, and familiar menu do not establish that Apple operates a page.<\/p>\n<p>Apple preorders belong on Apple&#8217;s verified site or an authorized retailer&#8217;s established domain. A social ad or unfamiliar link can imitate both.<\/p>\n<div id=\"mwtad4022068825\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>The suspicious page offered details that did not match the real preorder process. Its countdown restarted, and its policy links led nowhere.<\/p>\n<p>In the version examined, pressing the final button produced a success message without processing a genuine order. The preorder was scenery around the attack.<\/p>\n<div id=\"mwtad3989283920\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Fake iPhone Duo Preorder Scam Works<\/h2>\n<h3>Step 1: A remarkable offer finds the right audience<\/h3>\n<p>New product launches generate searches, videos, rumors, and hurried conversations. Fraudulent pages thrive when people are already expecting fresh announcements.<\/p>\n<div id=\"mwtad4289133734\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>A $500 voucher gives the visitor a reason to move quickly. It sounds like a promotional benefit rather than a warning sign.<\/p>\n<p>The page Malwarebytes examined used an Apple-like appearance and a deadline. It asked visitors to select a model and provide contact details.<\/p>\n<p>That sequence feels normal for a reservation. Someone might reasonably think the page is collecting interest before a product becomes available.<\/p>\n<div id=\"mwtad1387172587\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>But a deal that appears only through a stray ad or shared link deserves independent verification. The visible design can be copied in hours.<\/p>\n<p>Check the destination through Apple&#8217;s own website, not by clicking another button on the promotional page. The page cannot verify itself.<\/p>\n<h3>Step 2: The page steers visitors toward Safari<\/h3>\n<p>The attack code was designed around iPhones and Safari. Visitors using other browsers could see a restriction message urging them to open the page differently.<\/p>\n<p>On an iPhone, the page also attempted to reopen itself in Safari. That behavior was not necessary to reserve a phone.<\/p>\n<p>It served the attacker&#8217;s preferred technical environment. A legitimate retail page should not need a particular browser to display a simple preorder form.<\/p>\n<p>Researchers also noted that background resources might load in some other browsers. Seeing a restriction notice does not automatically make the visit harmless.<\/p>\n<p>Do not treat a request to switch browsers as helpful customer support. Close the page and check the offer from a known address.<\/p>\n<h3>Step 3: The hidden code checks the phone<\/h3>\n<p>An invisible frame on the page examined the visitor&#8217;s iOS version and selected additional code to load.<\/p>\n<p>This is the crucial difference from an ordinary fake checkout. The attack did not have to wait for a tap on the preorder button.<\/p>\n<p>DarkSword is an exploit chain aimed at weaknesses in older iOS versions. It tries to break through layers that normally keep websites isolated.<\/p>\n<p>Apple has patched the reported weaknesses. A current update substantially changes the risk compared with an unpatched phone in the targeted range.<\/p>\n<p>The precise outcome for an individual visitor depends on device version, patch status, browser behavior, and whether the exploit succeeds.<\/p>\n<p>No article can determine infection merely from a URL in someone&#8217;s history. The right response is prompt, proportionate investigation.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1672\" height=\"941\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Illustrative iOS Software Update screen with automatic updates enabled\" class=\"wp-image-421632 lazyload\" title=\"\" sizes=\"auto, (max-width: 1672px) 100vw, 1672px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-detail-v3.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-detail-v3.png 1672w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-detail-v3-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-detail-v3-1024x576.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/iphone-detail-v3-1536x864.png 1536w\"><\/figure>\n<h3>Step 4: The payload attempts to reach private data<\/h3>\n<p>Malwarebytes found code designed to gather device information and lists of installed applications. It also targeted Apple Notes and cryptocurrency wallets.<\/p>\n<p>The code looked for wallet applications such as MetaMask, Phantom, Trust Wallet, Coinbase Wallet, Exodus, and Tonkeeper.<\/p>\n<p>It attempted to recover keychain credentials and send selected wallet data if earlier communication with its server succeeded.<\/p>\n<p>Other targeted material included photos, messages, contacts, call history, email, calendar entries, and cached location information.<\/p>\n<p>These are attempted capabilities observed in code, not a public list of confirmed victims or stolen records.<\/p>\n<p>The distinction should reassure neither complacent readers nor alarmed ones. A failed attack is possible, but so is a successful one on a vulnerable device.<\/p>\n<h3>Step 5: The site keeps the preorder story going<\/h3>\n<p>The form and its confirmation help the page appear useful after the exploit has already started in the background.<\/p>\n<p>In the captured version, submitting the form did not create a real preorder. The site&#8217;s own code displayed a success message.<\/p>\n<p>That means someone could leave believing they reserved a phone while missing the security event that mattered.<\/p>\n<p>The form itself still invited the visitor to type personal details. The inspected copy did not transmit those entries, but other copies could behave differently.<\/p>\n<p>Do not assume a harmless form simply because one analyzed version had an empty submission handler. Attackers can change pages without notice.<\/p>\n<p>A genuine order should produce confirmation through the retailer&#8217;s verified account and official channels, not just a message on a suspicious page.<\/p>\n<h3>Step 6: The attacker may use whatever access remains<\/h3>\n<p>The analyzed payload could contact its server for instructions and retrieve more information from the device.<\/p>\n<p>Researchers found no automatic persistence mechanism that would necessarily survive a restart. That finding is useful, but it is not a guarantee.<\/p>\n<p>Restarting cannot retrieve information already sent out. It also cannot undo a stolen password or compromised wallet.<\/p>\n<p>For that reason, a reader who opened the site on an old, unpatched iPhone should update first, then address accounts and funds from a trusted device.<\/p>\n<p>Be especially careful with recovery messages. Someone offering to diagnose an iPhone through a random direct message may be a second scammer.<\/p>\n<div id=\"mwtad3869040477\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What Makes This Preorder Different From an Ordinary Fake Store<\/h2>\n<p>Many fake product pages want card numbers. This one combined an enticing product story with a technical attempt to exploit the browser.<\/p>\n<p>That makes the usual advice, &#8220;Do not enter your card,&#8221; incomplete. The visitor might face risk without typing anything.<\/p>\n<p>It also changes how evidence should be interpreted. A fake confirmation screen is not proof of an order, but it can distract from the page&#8217;s background behavior.<\/p>\n<p>Malwarebytes did not see the captured page transmit the form contents. Calling it a confirmed card theft page would overstate the case.<\/p>\n<p>The research supports a narrower, serious conclusion: the page attempted a drive-by attack against vulnerable iPhones.<\/p>\n<p>A well-patched device may resist that chain. That is why software status matters more here than the quality of the fake logo.<\/p>\n<p>People who opened the link on a desktop computer should not assume the exact iPhone exploit ran there. Still, avoid revisiting the site.<\/p>\n<p>People who shared the link should warn recipients without reposting an active malicious URL. Send a plain warning and the official Apple address instead.<\/p>\n<div id=\"mwtad3818143900\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Check a New iPhone Offer Safely<\/h2>\n<p>Start at Apple&#8217;s website by typing the address yourself or using a trusted bookmark. Navigate to the product from there.<\/p>\n<p>For a retailer promotion, verify the retailer&#8217;s real domain separately. An advertiser&#8217;s display name can differ from the actual destination.<\/p>\n<p>Compare the date, model options, prices, and preorder availability with the official listing. A page claiming privileged early access needs strong evidence.<\/p>\n<p>Do not rely on a padlock. HTTPS protects a connection to a website; it does not prove who owns the website.<\/p>\n<p>Watch for decorative details that fail basic checks. A countdown that resets, broken policy links, or invented colors make the offer less credible.<\/p>\n<p>Ask why a retailer would need WhatsApp or unusual contact details for a normal preorder. Extra channels can also support follow-up impersonation.<\/p>\n<p>Check whether the promotion exists through the retailer&#8217;s official support pages, not through a phone number or chat widget on the suspicious page.<\/p>\n<p>Search results may contain paid placements that resemble ordinary listings. An ad label is not a safety certificate, and an advertiser can change its landing page later.<\/p>\n<p>When a friend forwards a preorder link, ask where they found it. A shared message can spread an unsafe page without the sender realizing what it does.<\/p>\n<p>Save a screenshot only if you can do so without reopening the page. The web address and visit time are more useful to responders than a polished product image.<\/p>\n<p>If the page insists you disable protections, change browsers, install a profile, or open a special file, leave immediately.<\/p>\n<p>Keep iOS and Safari up to date even when you do not expect to encounter a suspicious ad. Here, patching was a meaningful defense.<\/p>\n<div id=\"mwtad1755152632\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Opened the Fake Preorder Page<\/h2>\n<p>Take a breath. Opening the page does not establish that the exploit succeeded, but delaying updates and account protection is not helpful.<\/p>\n<ol>\n<li><strong>Leave the page and preserve its address.<\/strong> Close it without returning. Save the link from your history or message if safe, and record when you visited.<\/li>\n<li><strong>Update the iPhone.<\/strong> Open Settings, General, then Software Update. Install the newest version available for the device and restart after updating.<\/li>\n<li><strong>Use a trusted device for sensitive changes.<\/strong> Change the passwords for email, Apple Account, banking, and any account stored on that phone. Review active sessions.<\/li>\n<li><strong>Protect cryptocurrency funds.<\/strong> If the exposed phone held wallet keys, create a new wallet on a trusted device and move remaining assets. Contact exchanges promptly.<\/li>\n<li><strong>Review financial and account activity.<\/strong> Look for unfamiliar sign-ins, transfers, recovery changes, and new devices. Contact each provider through its verified support route.<\/li>\n<li><strong>Check for related threats.<\/strong> Malwarebytes can help inspect other affected devices or browsing exposure; AdGuard can block known malicious destinations. Neither replaces an iOS update.<\/li>\n<li><strong>Report the page.<\/strong> Send the URL and your observations to Apple and your national cybercrime reporting service. Avoid sharing private wallet keys or passwords.<\/li>\n<\/ol>\n<p>If you entered only contact details, watch for follow-up texts and calls claiming your preorder needs a deposit or identity check.<\/p>\n<p>If you installed a profile or app after visiting, mention that fact to a qualified responder. It changes the investigation beyond the web exploit described here.<\/p>\n<p>Do not pay a stranger to &#8220;unlock&#8221; your phone or recover coins. A second payment request is often another attempt at theft.<\/p>\n<div id=\"mwtad84324472\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Frequently Asked Questions<\/h2>\n<h3>Is the iPhone Duo preorder page an Apple promotion?<\/h3>\n<p>No. The page Malwarebytes analyzed imitated Apple&#8217;s style but was not an official Apple preorder.<\/p>\n<p>Verify any offer by visiting Apple directly. Logos, product renders, and a familiar navigation bar are easy to imitate.<\/p>\n<h3>Can a page harm an iPhone if I never tap Preorder?<\/h3>\n<p>The analyzed page attempted to load an exploit on vulnerable phones before form submission. Whether it succeeds depends on the device and patches.<\/p>\n<p>That is why closing the page, updating iOS, and reviewing sensitive accounts are sensible steps even without a completed form.<\/p>\n<h3>Was the $500 voucher real?<\/h3>\n<p>Researchers found no genuine preorder behind the inspected page. Its visible $500 offer was part of the lure.<\/p>\n<p>Do not infer that every $500 retailer promotion is fake. Confirm each offer through the retailer&#8217;s independently reached site.<\/p>\n<h3>Did the fake form steal my name and phone number?<\/h3>\n<p>Malwarebytes reported that the captured copy did not read or send those form entries when submitted.<\/p>\n<p>That finding applies to the version examined. A changed or copied page could collect details, so remain alert for follow-up messages.<\/p>\n<h3>Will restarting the iPhone solve everything?<\/h3>\n<p>The analyzed code showed no automatic restart persistence, but restarting cannot undo data already copied or restore a compromised wallet.<\/p>\n<p>Update the phone, restart it, and secure accounts and funds from a trusted device. Seek specialist help if evidence suggests compromise.<\/p>\n<h3>How can I tell whether my phone was infected?<\/h3>\n<p>A visit alone cannot confirm infection. Warning signs may be absent, and the public research did not provide a simple self-test.<\/p>\n<p>Document the visit, update promptly, review accounts, and contact Apple or a reputable incident responder if the phone held especially sensitive information.<\/p>\n<div id=\"mwtad1429323439\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Bottom Line<\/h2>\n<p>The fake preorder made a $500 voucher look like the story. The more serious issue was code that attempted to exploit vulnerable iPhones on page load.<\/p>\n<p>Check promotions through official sites, keep iOS current, and treat an unfamiliar preorder link as a security question before it becomes a purchase decision.<\/p>\n<div id=\"mwtad2115775778\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A $500 preorder voucher sounds tempting when a new phone has barely been announced. The page looks familiar enough to invite a quick glance. Before you decide whether that offer deserves your details, notice what &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake iPhone Duo Preorder Scam Exposed: $500 Voucher Hides DarkSword Attack\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fake-iphone-duo-preorder-darksword-attack\/#more-421630\" aria-label=\"Read more about Fake iPhone Duo Preorder Scam Exposed: $500 Voucher Hides DarkSword Attack\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":421631,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-421630","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/421630","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=421630"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/421630\/revisions"}],"predecessor-version":[{"id":421633,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/421630\/revisions\/421633"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/421631"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=421630"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=421630"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=421630"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}