iPhone Duo Scam Alert: What Buyers Should Know About the Fake Preorder Scheme
Fake preorder site embeds malware targeting older iPhones. Here's what buyers need to know.
A dangerous new scam targeting potential iPhone buyers has emerged online, and it’s designed to look almost identical to Apple’s official website. Security researchers have uncovered a fraudulent preorder campaign for the iPhone Duo that combines sophisticated web design with malicious code to steal sensitive data from unsuspecting visitors.
The Fake iPhone Duo Preorder Scam
Cybersecurity experts recently discovered a malicious website offering a $500 voucher for iPhone Duo preorders. The site mimics Apple’s branding and design so closely that distinguishing it from a legitimate Apple page requires careful attention. To create urgency, the scammers included a countdown timer suggesting the offer would expire soon, a common pressure tactic used to bypass critical thinking.
The real danger lies beneath the surface. Simply visiting the page triggers embedded malicious code that immediately begins scanning your device for sensitive information. The exploit, known as DarkSword, searches for cryptocurrency wallets, saved passwords stored in your device’s keychain, call history, voicemail, contacts, location data, and personal messages. The malware also attempts to cover its tracks by deleting logs that could reveal the infection.
Once activated, the code calls home regularly to receive instructions on what additional data to capture and exfiltrate from your device. This persistent communication allows the criminals behind the scam to adapt their attack and maximize the amount of personal and financial information they steal.
Who Is at Risk

The DarkSword exploit primarily targets older devices or those running outdated iOS versions. If you use Safari on an older iPhone or iPad that hasn’t been updated recently, you face the highest risk. The scammers are aware of this limitation, so the fake site attempts to redirect users who arrive via alternative browsers like Chrome or Firefox back to Safari by falsely claiming those browsers aren’t supported.
The good news is that Apple users with current devices and current software versions running any browser other than Safari are largely protected. However, the sophistication of the scam means even tech-savvy shoppers could accidentally click a link from social media, email, or search results.
How to Protect Yourself
If you’re considering purchasing an iPhone Duo or any Apple product, follow these essential safety practices:
- Always verify you’re on Apple’s official website by checking the URL carefully. Apple’s domain is apple.com, nothing else. Scammers often use slightly misspelled variations like appie.com or apple-official.com.
- Keep your iOS software updated to the latest version available for your device. Apple regularly patches security vulnerabilities, and running outdated software leaves you exposed.
- Use a browser other than Safari when browsing on older devices, as DarkSword specifically targets Safari.
- Never click links to Apple products or services from unsolicited emails or social media posts. Instead, open a fresh browser window and navigate directly to apple.com.
- Be suspicious of any offer that seems too good to be true. A $500 voucher for a device preorder far exceeds typical promotional offers from major brands.
- Enable two-factor authentication on your Apple ID and any cryptocurrency or financial accounts. This adds a critical layer of protection even if scammers obtain your password.
Broader Security Context

This scam is part of a larger pattern of cybercriminals targeting smartphone buyers. As demand for the latest iPhone models continues growing, scammers are investing in increasingly sophisticated fake sites and social engineering tactics. They understand that product launches create excitement and urgency, emotions that cloud judgment.
Researchers have observed similar campaigns targeting other premium device releases over the past year. The combination of fake preorder vouchers, countdown timers, and embedded malware has become a playbook for criminal organizations operating internationally. Law enforcement agencies across multiple countries are actively investigating these networks, but the borderless nature of cybercrime makes prosecution challenging.
What Happens If You Clicked the Link
If you accidentally visited the fraudulent site before realizing your mistake, take immediate action. Update your iOS to the latest version if you haven’t already. Change your passwords for any cryptocurrency wallets, banking apps, email accounts, and other sensitive services from a different device. Monitor your accounts for suspicious activity, unusual transactions, or unauthorized logins.
Consider enabling additional security features offered by your banks and online services, such as purchase notifications or spending alerts. If you notice unauthorized transactions, contact your financial institution immediately.
For additional protection when shopping for iPhone accessories and devices, research retailers carefully before providing any personal information or payment details. Stick with authorized Apple retailers, major electronics retailers with established reputations, and official Apple channels.
Product launches are exciting events for technology enthusiasts, but they also create opportunities for criminals. By understanding how these scams operate and taking basic precautions, you can enjoy the latest innovations without compromising your security or personal data.
