A newly surfaced OTX pulse documents an active drive-by exploitation campaign weaponizing the hype around a purported "iPhone Duo" preorder launch. Fraudulent landing pages — pixel-perfect clones of Apple's storefront — promise visitors a $500 voucher to lure iPhone users into simply loading the page in Safari. No tap, no download, no consent prompt is required: rendering the page is sufficient to trigger the DarkSword exploit chain, which attempts to escape WebKit's sandbox and execute native payloads on devices running unpatched iOS builds.
The campaign is a classic watering-hole-meets-social-engineering hybrid. Rather than mass phishing blasts, the operators rely on search poisoning, malvertising, and social reposts around preorder season — a period when users expect promotional offers and lower their guard. Post-exploitation objectives align with credential theft and cryptocurrency wallet draining: session tokens, iCloud Keychain material accessible post-sandbox-escape, wallet app data, and MFA seed artifacts are the high-value targets. The single C2/staging indicator — cloud.cmatgldn.click — uses a fast-flux-style disposable TLD (.click), consistent with infrastructure built for a short, high-velocity campaign window timed to a product launch news cycle.
For enterprise defenders, this matters beyond consumer risk: compromised personal iPhones connected to corporate MDM, accessing M365/Google Workspace sessions, or carrying cached SSO tokens become lateral-movement primitives into the enterprise identity perimeter.
Threat Actor / Malware Profile
Attribution: Unknown. The pulse lists no named adversary. The tradecraft — exploit chain delivery through promotional lure pages, disposable .click infrastructure, and crypto-theft monetization — is consistent with financially motivated exploit brokers rather than state-nexus espionage actors.
DarkSword exploit chain profile:
- Distribution: Fake Apple preorder pages seeded via social engineering, search ads, and link sharing. Initial access is a zero-click WebKit/Safari render — the exploit fires on page load with no user interaction.
- Payload behavior: Sandbox escape from WebContent process, arbitrary native code execution, then credential and crypto-wallet harvesting. Likely deploys a lightweight in-memory stager to minimize disk artifacts.
- C2 communication: Staging/beaconing through attacker-controlled hostnames such as
cloud.cmatgldn.click. Expect HTTPS beaconing with domain-fronting-style subdomains to blend with CDN traffic. - Persistence: On iOS, true persistence is constrained; DarkSword-class chains typically re-infect on revisit or abuse malicious configuration profiles / rogue MDM enrollment on unlocked devices. On macOS Safari victims, persistence may shift to LaunchAgents.
- Anti-analysis: Conditional execution based on user-agent, iOS version fingerprinting, and geolocation — the page renders a benign voucher scam to non-target clients. Exploit code is heavily obfuscated JavaScript delivered only after a successful device fingerprint.
IOC Analysis
The pulse carries one confirmed indicator:
| Type | Indicator | Notes |
|---|---|---|
| hostname | cloud.cmatgldn.click | DarkSword staging/C2; disposable .click TLD, resolve-and-block |
Operationalization guidance for SOC teams:
- DNS layer is your highest-fidelity control. Sinkhole or block
*.cmatgldn.clickat the recursive resolver and DNS firewall. Hostname IOCs for exploit kits have a short half-life, but DNS query logs retain retro-hunt value for months. - Pivot on the parent domain (
cmatgldn.click) — expect sibling subdomains for payload staging, exfil, and redirectors. - Enrich against passive DNS (SecurityTrails, CIRCL pDNS, VirusTotal) to harvest resolution IPs, then hunt NetFlow/proxy logs for those IPs.
- Feed the hostname into your EDR's custom indicator list (Defender, CrowdStrike, SentinelOne all support custom domain IOAs) and into SWG/proxy blocklists (Zscaler, Umbrella, PAN-OS URL filtering).
- Because delivery is WebKit-based, correlate DNS hits to the IOC with
com.apple.WebKit/ Safari /MobileSafariprocess attribution wherever your telemetry permits.
Detection Engineering
---
title: DNS Query to DarkSword C2 Infrastructure
id: 3f8a1c2e-9b41-4d77-a5e2-darksword001
status: experimental
description: Detects DNS resolution attempts for the DarkSword exploit chain staging/C2 domain associated with fake iPhone Duo preorder pages
author: Security Arsenal Threat Intel
references:
- https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-iphone-duo-preorder-scam-triggers-darksword-attack
date: 2026/09/30
logsource:
category: dns
detection:
selection:
query|contains:
- 'cmatgldn.click'
condition: selection
falsepositives:
- Threat intel researchers detonating the lure page in a sandbox
level: high
tags:
- attack.command_and_control
- attack.t1071.001
---
title: WebKit Child Process Spawning Shell or Script Interpreter
id: 7c2d4f91-3a58-4e12-b6d4-darksword002
status: experimental
description: Detects suspicious child processes spawned by Safari/WebKit processes on macOS, consistent with DarkSword post-sandbox-escape execution
author: Security Arsenal Threat Intel
date: 2026/09/30
logsource:
category: process_creation
product: macos
detection:
selection_parent:
ParentImage|contains:
- 'com.apple.WebKit'
- 'Safari'
selection_child:
Image|endswith:
- '/sh'
- '/zsh'
- '/bash'
- '/python'
- '/python3'
- '/osascript'
- '/curl'
- '/launchctl'
condition: all of selection_*
falsepositives:
- Rare; Safari does not normally spawn shell interpreters
level: critical
tags:
- attack.execution
- attack.t1059
- attack.t1189
---
title: Suspicious LaunchAgent Persistence Created by Browser Process
id: 91be03c7-6f24-4a89-c1a5-darksword003
status: experimental
description: Detects LaunchAgent plist creation attributable to browser processes, a post-exploitation persistence pattern for Safari-delivered macOS payloads
author: Security Arsenal Threat Intel
date: 2026/09/30
logsource:
category: file_event
product: macos
detection:
selection_path:
TargetFilename|contains:
- '/Library/LaunchAgents/'
- '~/Library/LaunchAgents/'
selection_image:
Image|contains:
- 'Safari'
- 'WebKit'
condition: all of selection_*
falsepositives:
- Legitimate browser helper installers (rare; validate signer)
level: high
tags:
- attack.persistence
- attack.t1543.001
// Hunt: DarkSword C2 contact + suspicious browser network behavior
let DarkSwordIOCs = dynamic(["cmatgldn.click", "cloud.cmatgldn.click"]);
let DnsHits =
DeviceNetworkEvents
| where Timestamp > ago(14d)
| where RemoteUrl has_any (DarkSwordIOCs) or RemoteUrl endswith ".click"
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteUrl, RemoteIP, ActionType;
let BrowserNet =
DeviceNetworkEvents
| where Timestamp > ago(14d)
| where InitiatingProcessFileName in~ ("safari", "com.apple.webkit.networking", "com.apple.webkit.webcontent", "chrome.exe", "msedge.exe")
| where RemoteUrl endswith ".click"
| summarize Connections=count(), FirstSeen=min(Timestamp), LastSeen=max(Timestamp), RemoteIPs=make_set(RemoteIP) by DeviceName, InitiatingProcessFileName, RemoteUrl;
union DnsHits, BrowserNet
| order by Timestamp desc
#!/bin/bash
# DarkSword IOC Hunt — checks DNS cache/logs, proxy logs, and macOS persistence locations
# Run with sudo on macOS endpoints or against exported log archives
IOC_DOMAIN="cmatgldn.click"
REPORT="darksword_hunt_$(date +%Y%m%d_%H%M%S).txt"
echo "=== DarkSword IOC Hunt Report ===" | tee "$REPORT"
echo "Hostname: $(hostname) | Date: $(date)" | tee -a "$REPORT"
echo -e "\n[1] DNS cache / resolver log check for $IOC_DOMAIN" | tee -a "$REPORT"
if command -v dscacheutil &>/dev/null; then
dscacheutil -q host -a name "cloud.$IOC_DOMAIN" 2>/dev/null | tee -a "$REPORT"
fi
grep -ri "$IOC_DOMAIN" /var/log/ 2>/dev/null | head -20 | tee -a "$REPORT"
echo -e "\n[2] Active network connections to .click TLDs" | tee -a "$REPORT"
if command -v netstat &>/dev/null; then
netstat -anv 2>/dev/null | grep -i "\.click" | tee -a "$REPORT"
fi
lsof -i 2>/dev/null | grep -i "click" | tee -a "$REPORT"
echo -e "\n[3] Suspicious LaunchAgents (recent, unsigned-looking names)" | tee -a "$REPORT"
for dir in /Library/LaunchAgents /Library/LaunchDaemons ~/Library/LaunchAgents; do
if [ -d "$dir" ]; then
find "$dir" -name "*.plist" -mtime -14 -exec ls -la {} \; 2>/dev/null | tee -a "$REPORT"
fi
done
echo -e "\n[4] Safari history artifacts referencing lure or C2 domains" | tee -a "$REPORT"
HIST_DB="$HOME/Library/Safari/History.db"
if [ -f "$HIST_DB" ]; then
cp "$HIST_DB" /tmp/hist_copy.db 2>/dev/null
sqlite3 /tmp/hist_copy.db "SELECT url, visit_time FROM history_visits v JOIN history_items i ON v.history_item=i.id WHERE url LIKE '%cmatgldn%' OR url LIKE '%iphone-duo%' OR url LIKE '%preorder%';" 2>/dev/null | tee -a "$REPORT"
rm -f /tmp/hist_copy.db
fi
echo -e "\n[5] Unified log sweep (last 24h) for WebKit exploitation indicators" | tee -a "$REPORT"
if command -v log &>/dev/null; then
log show --last 24h --predicate 'process == "com.apple.WebKit.WebContent" AND eventMessage CONTAINS[c] "sandbox"' 2>/dev/null | grep -i "violation\|deny\|escape" | head -20 | tee -a "$REPORT"
fi
echo -e "\n=== Hunt complete. Review $REPORT ===" | tee -a "$REPORT"
Response Priorities
Immediate (0–4 hours):
- Block
*.cmatgldn.clickat DNS firewall, secure web gateway, and EDR custom indicators; sinkhole at the recursive resolver to surface infected devices via DNS query attribution. - Retro-hunt DNS and proxy logs for 14 days against the IOC and parent domain; isolate any endpoint with confirmed resolution and capture volatile memory before remediation.
- Push emergency iOS/iPadOS/macOS patch compliance enforcement via MDM — the exploit only lands on unpatched builds, so patch posture is the single decisive control.
24 hours:
- Treat any device that resolved the C2 as fully compromised at the identity layer: force revocation of iCloud, M365, Google Workspace, and SSO sessions; reset credentials for accounts accessed from affected devices.
- Review MFA registrations and crypto-wallet app activity on affected devices; hunt for anomalous token use from impossible-travel or new-device logins.
- Audit MDM enrollment logs for rogue configuration profiles or unexpected device enrollments in the exposure window.
1 week:
- Enforce automatic OS updates and minimum-OS-version conditional access policies so unpatched iOS devices cannot reach corporate resources.
- Deploy DNS-layer filtering of newly registered domains and high-risk disposable TLDs (
.click,.top,.xyz) for browser traffic. - Add Safari/WebKit child-process telemetry to your EDR coverage on macOS fleets; run tabletop on mobile-compromise-to-identity-compromise escalation paths.
- Launch targeted user awareness: preorder-season lure pages, voucher scams, and the fact that no interaction is required for compromise.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.