Security Researchers Uncover New Spyware Implant TriangleDB

Kaspersky security researchers recently discovered an advanced spyware implant called TriangleDB that is part of an operation known as Triangulation.

The implant specifically targets iOS devices via malicious iMessage attachments, according to the advisory issued by the company today. It is deployed after an attacker exploits a kernel vulnerability to gain root privileges.

Attack Details Targeting iOS Devices: New Zero-Click iOS Exploit Introduces Israeli Spyware

Once TriangleDB is installed, it resides in device memory, making it difficult to detect. At the same time, rebooting the device effectively removes it. If no reboot takes place (unless the attacker extends the period), the implant will automatically uninstall after his 30 days.

TriangleDB is coded using Objective-C and uses the Protobuf library to communicate with a command and control (C2) server. Messages exchanged between the implant and the server are encrypted using symmetric and asymmetric encryption.

The C2 server sends commands to the implant, which are then executed to perform various tasks.

These commands include interacting with the device’s file system, monitoring processes, retrieving keychain items, tracking geolocation, and running additional modules.

One notable command discovered monitors a specified directory for modified files that match a specific regular expression. These files are scheduled for extraction to the C2 server.

Further analysis is underway on the TriangleDB implant, and Kaspersky researchers said they will continue to investigate to gather details about the campaign.

“We are continuing to analyze the campaign and will keep you updated with further insights into this sophisticated attack,” said Georgie Kucherin, a security expert in Kaspersky’s Global Research and Analysis Team (GReAT). says.

“We call on the cybersecurity community to come together, share knowledge and work together to get a clearer picture of the threats out there.”

The TriangleDB advisory comes a few weeks after Kaspersky released a new automated tool that allows iOS users to test their devices for specific malware from Operation Triangulation.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *