Back to Intelligence

DarkSword Exploit Chain via Fake iPhone Duo Preorder Pages: OTX Pulse Analysis — Safari Zero-Click Detection Pack

SA
Security Arsenal Team
September 29, 2026
8 min read

A newly surfaced OTX pulse documents an active drive-by exploitation campaign weaponizing the hype around a purported "iPhone Duo" preorder launch. Fraudulent landing pages — pixel-perfect clones of Apple's storefront — promise visitors a $500 voucher to lure iPhone users into simply loading the page in Safari. No tap, no download, no consent prompt is required: rendering the page is sufficient to trigger the DarkSword exploit chain, which attempts to escape WebKit's sandbox and execute native payloads on devices running unpatched iOS builds.

The campaign is a classic watering-hole-meets-social-engineering hybrid. Rather than mass phishing blasts, the operators rely on search poisoning, malvertising, and social reposts around preorder season — a period when users expect promotional offers and lower their guard. Post-exploitation objectives align with credential theft and cryptocurrency wallet draining: session tokens, iCloud Keychain material accessible post-sandbox-escape, wallet app data, and MFA seed artifacts are the high-value targets. The single C2/staging indicator — cloud.cmatgldn.click — uses a fast-flux-style disposable TLD (.click), consistent with infrastructure built for a short, high-velocity campaign window timed to a product launch news cycle.

For enterprise defenders, this matters beyond consumer risk: compromised personal iPhones connected to corporate MDM, accessing M365/Google Workspace sessions, or carrying cached SSO tokens become lateral-movement primitives into the enterprise identity perimeter.

Threat Actor / Malware Profile

Attribution: Unknown. The pulse lists no named adversary. The tradecraft — exploit chain delivery through promotional lure pages, disposable .click infrastructure, and crypto-theft monetization — is consistent with financially motivated exploit brokers rather than state-nexus espionage actors.

DarkSword exploit chain profile:

  • Distribution: Fake Apple preorder pages seeded via social engineering, search ads, and link sharing. Initial access is a zero-click WebKit/Safari render — the exploit fires on page load with no user interaction.
  • Payload behavior: Sandbox escape from WebContent process, arbitrary native code execution, then credential and crypto-wallet harvesting. Likely deploys a lightweight in-memory stager to minimize disk artifacts.
  • C2 communication: Staging/beaconing through attacker-controlled hostnames such as cloud.cmatgldn.click. Expect HTTPS beaconing with domain-fronting-style subdomains to blend with CDN traffic.
  • Persistence: On iOS, true persistence is constrained; DarkSword-class chains typically re-infect on revisit or abuse malicious configuration profiles / rogue MDM enrollment on unlocked devices. On macOS Safari victims, persistence may shift to LaunchAgents.
  • Anti-analysis: Conditional execution based on user-agent, iOS version fingerprinting, and geolocation — the page renders a benign voucher scam to non-target clients. Exploit code is heavily obfuscated JavaScript delivered only after a successful device fingerprint.

IOC Analysis

The pulse carries one confirmed indicator:

TypeIndicatorNotes
hostnamecloud.cmatgldn.clickDarkSword staging/C2; disposable .click TLD, resolve-and-block

Operationalization guidance for SOC teams:

  • DNS layer is your highest-fidelity control. Sinkhole or block *.cmatgldn.click at the recursive resolver and DNS firewall. Hostname IOCs for exploit kits have a short half-life, but DNS query logs retain retro-hunt value for months.
  • Pivot on the parent domain (cmatgldn.click) — expect sibling subdomains for payload staging, exfil, and redirectors.
  • Enrich against passive DNS (SecurityTrails, CIRCL pDNS, VirusTotal) to harvest resolution IPs, then hunt NetFlow/proxy logs for those IPs.
  • Feed the hostname into your EDR's custom indicator list (Defender, CrowdStrike, SentinelOne all support custom domain IOAs) and into SWG/proxy blocklists (Zscaler, Umbrella, PAN-OS URL filtering).
  • Because delivery is WebKit-based, correlate DNS hits to the IOC with com.apple.WebKit / Safari / MobileSafari process attribution wherever your telemetry permits.

Detection Engineering

YAML
---
title: DNS Query to DarkSword C2 Infrastructure
id: 3f8a1c2e-9b41-4d77-a5e2-darksword001
status: experimental
description: Detects DNS resolution attempts for the DarkSword exploit chain staging/C2 domain associated with fake iPhone Duo preorder pages
author: Security Arsenal Threat Intel
references:
    - https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-iphone-duo-preorder-scam-triggers-darksword-attack
date: 2026/09/30
logsource:
    category: dns
detection:
    selection:
        query|contains:
            - 'cmatgldn.click'
    condition: selection
falsepositives:
    - Threat intel researchers detonating the lure page in a sandbox
level: high
tags:
    - attack.command_and_control
    - attack.t1071.001
---
title: WebKit Child Process Spawning Shell or Script Interpreter
id: 7c2d4f91-3a58-4e12-b6d4-darksword002
status: experimental
description: Detects suspicious child processes spawned by Safari/WebKit processes on macOS, consistent with DarkSword post-sandbox-escape execution
author: Security Arsenal Threat Intel
date: 2026/09/30
logsource:
    category: process_creation
    product: macos
detection:
    selection_parent:
        ParentImage|contains:
            - 'com.apple.WebKit'
            - 'Safari'
    selection_child:
        Image|endswith:
            - '/sh'
            - '/zsh'
            - '/bash'
            - '/python'
            - '/python3'
            - '/osascript'
            - '/curl'
            - '/launchctl'
    condition: all of selection_*
falsepositives:
    - Rare; Safari does not normally spawn shell interpreters
level: critical
tags:
    - attack.execution
    - attack.t1059
    - attack.t1189
---
title: Suspicious LaunchAgent Persistence Created by Browser Process
id: 91be03c7-6f24-4a89-c1a5-darksword003
status: experimental
description: Detects LaunchAgent plist creation attributable to browser processes, a post-exploitation persistence pattern for Safari-delivered macOS payloads
author: Security Arsenal Threat Intel
date: 2026/09/30
logsource:
    category: file_event
    product: macos
detection:
    selection_path:
        TargetFilename|contains:
            - '/Library/LaunchAgents/'
            - '~/Library/LaunchAgents/'
    selection_image:
        Image|contains:
            - 'Safari'
            - 'WebKit'
    condition: all of selection_*
falsepositives:
    - Legitimate browser helper installers (rare; validate signer)
level: high
tags:
    - attack.persistence
    - attack.t1543.001
KQL — Microsoft Sentinel / Defender
// Hunt: DarkSword C2 contact + suspicious browser network behavior
let DarkSwordIOCs = dynamic(["cmatgldn.click", "cloud.cmatgldn.click"]);
let DnsHits =
    DeviceNetworkEvents
    | where Timestamp > ago(14d)
    | where RemoteUrl has_any (DarkSwordIOCs) or RemoteUrl endswith ".click"
    | project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType;
let BrowserNet =
    DeviceNetworkEvents
    | where Timestamp > ago(14d)
    | where InitiatingProcessFileName in~ ("safari", "com.apple.webkit.networking", "com.apple.webkit.webcontent", "chrome.exe", "msedge.exe")
    | where RemoteUrl endswith ".click"
    | summarize Connections=count(), FirstSeen=min(Timestamp), LastSeen=max(Timestamp), RemoteIPs=make_set(RemoteIP) by DeviceName, InitiatingProcessFileName, RemoteUrl;
union DnsHits, BrowserNet
| order by Timestamp desc
Bash / Shell
#!/bin/bash
# DarkSword IOC Hunt — checks DNS cache/logs, proxy logs, and macOS persistence locations
# Run with sudo on macOS endpoints or against exported log archives

IOC_DOMAIN="cmatgldn.click"
REPORT="darksword_hunt_$(date +%Y%m%d_%H%M%S).txt"

echo "=== DarkSword IOC Hunt Report ===" | tee "$REPORT"
echo "Hostname: $(hostname) | Date: $(date)" | tee -a "$REPORT"

echo -e "\n[1] DNS cache / resolver log check for $IOC_DOMAIN" | tee -a "$REPORT"
if command -v dscacheutil &>/dev/null; then
    dscacheutil -q host -a name "cloud.$IOC_DOMAIN" 2>/dev/null | tee -a "$REPORT"
fi
grep -ri "$IOC_DOMAIN" /var/log/ 2>/dev/null | head -20 | tee -a "$REPORT"

echo -e "\n[2] Active network connections to .click TLDs" | tee -a "$REPORT"
if command -v netstat &>/dev/null; then
    netstat -anv 2>/dev/null | grep -i "\.click" | tee -a "$REPORT"
fi
lsof -i 2>/dev/null | grep -i "click" | tee -a "$REPORT"

echo -e "\n[3] Suspicious LaunchAgents (recent, unsigned-looking names)" | tee -a "$REPORT"
for dir in /Library/LaunchAgents /Library/LaunchDaemons ~/Library/LaunchAgents; do
    if [ -d "$dir" ]; then
        find "$dir" -name "*.plist" -mtime -14 -exec ls -la {} \; 2>/dev/null | tee -a "$REPORT"
    fi
done

echo -e "\n[4] Safari history artifacts referencing lure or C2 domains" | tee -a "$REPORT"
HIST_DB="$HOME/Library/Safari/History.db"
if [ -f "$HIST_DB" ]; then
    cp "$HIST_DB" /tmp/hist_copy.db 2>/dev/null
    sqlite3 /tmp/hist_copy.db "SELECT url, visit_time FROM history_visits v JOIN history_items i ON v.history_item=i.id WHERE url LIKE '%cmatgldn%' OR url LIKE '%iphone-duo%' OR url LIKE '%preorder%';" 2>/dev/null | tee -a "$REPORT"
    rm -f /tmp/hist_copy.db
fi

echo -e "\n[5] Unified log sweep (last 24h) for WebKit exploitation indicators" | tee -a "$REPORT"
if command -v log &>/dev/null; then
    log show --last 24h --predicate 'process == "com.apple.WebKit.WebContent" AND eventMessage CONTAINS[c] "sandbox"' 2>/dev/null | grep -i "violation\|deny\|escape" | head -20 | tee -a "$REPORT"
fi

echo -e "\n=== Hunt complete. Review $REPORT ===" | tee -a "$REPORT"

Response Priorities

Immediate (0–4 hours):

  • Block *.cmatgldn.click at DNS firewall, secure web gateway, and EDR custom indicators; sinkhole at the recursive resolver to surface infected devices via DNS query attribution.
  • Retro-hunt DNS and proxy logs for 14 days against the IOC and parent domain; isolate any endpoint with confirmed resolution and capture volatile memory before remediation.
  • Push emergency iOS/iPadOS/macOS patch compliance enforcement via MDM — the exploit only lands on unpatched builds, so patch posture is the single decisive control.

24 hours:

  • Treat any device that resolved the C2 as fully compromised at the identity layer: force revocation of iCloud, M365, Google Workspace, and SSO sessions; reset credentials for accounts accessed from affected devices.
  • Review MFA registrations and crypto-wallet app activity on affected devices; hunt for anomalous token use from impossible-travel or new-device logins.
  • Audit MDM enrollment logs for rogue configuration profiles or unexpected device enrollments in the exposure window.

1 week:

  • Enforce automatic OS updates and minimum-OS-version conditional access policies so unpatched iOS devices cannot reach corporate resources.
  • Deploy DNS-layer filtering of newly registered domains and high-risk disposable TLDs (.click, .top, .xyz) for browser traffic.
  • Add Safari/WebKit child-process telemetry to your EDR coverage on macOS fleets; run tabletop on mobile-compromise-to-identity-compromise escalation paths.
  • Launch targeted user awareness: preorder-season lure pages, voucher scams, and the fact that no interaction is required for compromise.

Related Resources

Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.