SlowMist Security Team identified a campaign targeting iOS Safari users on specific versions (18.4–18.6.2) via a fake VPS service landing page
SlowMist Security Team identified a campaign targeting iOS Safari users on specific versions (18.4–18.6.2) via a fake VPS service landing page. The decoy page loads JavaScript that screens for iPhones, potentially leading to asset theft from the DarkSword wallet.
- Protocols
- DarkSword
- Confidence
- High
- First seen
- 4 Sep 2026, 11:08 UTC