LSN News › India

Technology · India Bureau

Fraudulent iPhone Preorder Site Exploits Vulnerabilities to Target Crypto Assets

Security researchers have identified a scam operation using a counterfeit Apple device preorder website to exploit security flaws in iPhones and gain access to cryptocurrency wallets. The malicious site employs advanced exploitation techniques to compromise user data and digital assets.

LSN India · 1 October 2026

Cybersecurity firm Malwarebytes has uncovered a sophisticated phishing operation targeting Indian and regional smartphone users through a fake iPhone preorder portal. The fraudulent website leverages the DarkSword exploit chain, a known vulnerability framework, to infiltrate iPhones and extract sensitive information including device details and credentials.

The scam operates by luring users to a counterfeit Apple preorder page where they are prompted to enter personal and financial information. Once a user's device is compromised through the exploit chain, attackers gain unauthorized access to the device's data repositories, including cryptocurrency wallet credentials and authentication tokens stored on affected phones.

Security analysts warn that users who have visited suspicious preorder websites or clicked on links from unverified sources should immediately review their device security and cryptocurrency account access logs. The attack particularly threatens individuals holding digital assets, as compromised wallets could result in significant financial losses.

Apple has not issued an official statement regarding this specific threat campaign. However, security experts recommend users ensure their devices run the latest iOS updates, enable two-factor authentication on all accounts, and avoid accessing financial services through unsecured networks. Users suspecting compromise are advised to contact Apple Support and their financial institutions immediately.