New Report Exposes Operation Triangulation’s Spyware Implant Targeting iOS Devices

June 21, 2023Ravi LakshmananMobile Security/Spyware

Implanted spyware targeting iOS devices

More details have surfaced about a spyware implant being delivered to iOS devices as part of a campaign called “Operation Triangulation.”

Kaspersky, which discovered the operation after being one of the targets earlier this year, said the malware has a lifespan of 30 days, after which it will be automatically uninstalled unless the attackers extend it.

Russian cybersecurity firm codenamed backdoor Triangle DB.

“The implant is deployed after an attacker exploits a kernel vulnerability to gain root privileges on the targeted iOS device,” Kaspersky researchers said in a new report released today.

cyber security

“Because it is deployed in memory, all traces of the implant are lost when the device is rebooted. So once the victim reboots the device, the attacker can send an iMessage containing the malicious attachment. You have to send it in to re-infect the device and start the whole thing.” Another chain of exploitation. ”

Operation Triangulation requires the use of a zero-click exploit through the iMessage platform, which gives the spyware complete control over the device and user data.

Kaspersky CEO Eugene Kaspersky previously said, “The attack was carried out using invisible iMessages with malicious attachments, exploiting many vulnerabilities in the iOS operating system. It can be used to run on devices and install spyware.”

“Spyware deployment is completely hidden and requires no user action.”

TriangleDB is written in Objective-C and forms the core of the secret framework. It is designed to establish an encrypted connection with a command and control (C2) server and periodically send heartbeat beacons containing device metadata.

The server-side responds to heartbeat messages with one of 24 commands that dump iCloud Keychain data and load additional Mach-O modules into memory so they can collect sensitive data.

This includes file contents, location information, installed iOS applications, running processes, and more. The attack chain culminates in the first message being erased to cover up the tracking.

upcoming webinars

🔐 Mastering API Security: Understanding Your True Attack Surface

Discover untapped vulnerabilities in your API ecosystem and take proactive steps towards ironclad security. Join us for an insightful webinar!

join the session

A closer look at the source code reveals that malware authors refer to string decryption as “unmanging”, renaming files (records), processes (schema), C2 servers (DB servers) and geolocation from database terminology. Some unusual aspects of assigning were revealed. Information (DB status).

Another thing to notice is the existence of the routine “populateWithFieldsMacOSOnly”. This method is not called anywhere on the iOS implant, but the naming convention also makes it possible for TriangleDB to be weaponized to target macOS devices.

Kaspersky researchers said that the implant requires multiple entitlements (permissions) from the operating system.

“Some things are not used in the code, such as access to the camera, microphone, address book, or interaction with the device via Bluetooth. Therefore, the capabilities granted by these entitlements may be implemented in modules. .”

At this time, it is unknown who is behind this campaign and its ultimate goal. In an earlier statement shared with The Hacker News, Apple said it “has never worked with governments to insert backdoors into Apple products and will not do so in the future.”

But the Russian government has accused the United States of infiltrating “thousands” of Apple devices belonging to domestic subscribers and foreign diplomats as part of what it describes as reconnaissance.

Did you enjoy this article? Follow us twitter You can read more exclusive content we post on LinkedIn.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *