The FSB claims Apple helped the NSA hack Russian diplomats' iPhones; Kaspersky: unknown malware leveraged zero-click exploits on iPhones running up to iOS 15.7
The report combines an unverified state allegation against Apple with Kaspersky’s technical finding of malware using zero-click iPhone exploits. It lands in a documented pattern of sophisticated iPhone targeting: researchers had already identified new zero-click iPhone exploits affecting iOS 15 and early iOS 16.
Apple faces a security and trust challenge in Russia, while the FSB’s claim puts the company at the center of an intelligence dispute it has not been shown to control.
Users on the affected iOS range face exposure to malware that requires no interaction, making patching and device-forensics capabilities immediately important for high-risk targets.
Second-order effects
Russian government organizations have a rationale to restrict Apple devices for work, shifting procurement and communications policies even though the FSB’s attribution remains an allegation.
The disclosure increases pressure on Apple and mobile-security researchers to identify and close zero-click attack paths, while making diplomatic and government users more likely to treat consumer phones as high-risk endpoints.
Third-order effects
If state agencies continue to tie mobile-device exploits to national-security claims, consumer device choice may increasingly be governed by sovereignty and trust considerations rather than product preferences alone.
The recurring discovery of zero-click iPhone chains points to a durable asymmetry: strong device security can reduce broad attacks, but well-resourced actors may still concentrate on a small number of high-value targets.
The trend: This is one data point in the growing securitization of smartphones, where zero-click vulnerabilities and contested attribution shape government technology policy.
Recently, I've been researching #OperationTriangulation, a very sophisticated campaign targeting iPhones of my colleagues. They have been infected (through zero-click exploits) with APT malware. Here are some results of our research: https://securelist.com/.... @bzvr_ @2igosha
UPDATE: Apple denies the accusations from the FSB: “We have never worked with any government to insert a backdoor into any Apple product and never will.” https://techcrunch.com/...
Another update: Kaspersky says it reached out to Apple this morning “before sending out the report to national CERTs.” In other worlds, they only reached out to Apple hours before they published the report. https://techcrunch.com/...
A big advantage of a BYOD policy is that these devices use the orgs infra at some point & may create interesting log entries (DNS, proxy) Sigma Rules for - DNS logs - Proxy logs https://github.com/... #EquationGroup Reports https://securelist.com/... https://www-fsb-ru.translate.…
We've discovered a new cyberattack against iOS devices called Triangulation. The attack starts with an zero-click #iMessage with a malicious attachment which, using a number of vulnerabilities in iOS, installs spyware. #IOSTriangulation Full story 👇 https://securelist.com/...
We updated the story with details provided by Kaspersky spokesperson. All the company's answers are below. More interesting ones: -Several dozen employees allegedly hacked -No attribution -Some exploits may have been 0days -Discovered early 2023 https://techcrunch.com/... [image]
New: Russia's FSB accuses US of hacking thousands of iPhones in Russia. Comes same day Kaspersky said someone targeted its own researchers' iPhones with sophisticated malware The indicators of compromise between the two are the same, Kaspersky noted to me https://www.vice.com/...
I asked Kaspersky if it had any coordination or communication with any parts of the Russian government regarding Kaspersky's announcement. This is what it said: ["When asked if Kaspersky had any coordination or communication with any parts of the Russian government regarding Kasp…
NEW: Kaspersky says government hackers broke into the iPhones of several of its employees, using a zero-click exploit delivered via iMessage. At this point, there's no information on who was behind the attacks. https://techcrunch.com/...
This type of accusations, which I refer to as quasi-attribution, are not unusual for Russian authorities. While somewhat specific, they lack technical detail For example in April, FSB accused U.S. & NATO of using Ukraine to launch cyber attacks on Russia https://twitter.com/...
Kommersant also recalls that in March, staffers of the domestic politics branch of the Presidential Administration were told to stop using iPhones https://www.kommersant.ru/...
Don't Indian elite use Apple phones as status symbol? They're screwed - being emperors without clothes, as NSA can get right inside their loin clothes & can smell it. Mother of all ironies is, US made our morons paranoid about Huawei. Aren't Arabs smarter? https://www.reuters.com…
So in other words, every IPhone on this planet is compromised and just waiting for that back door to be opened since it's apparent Apple hasn't secured this. https://twitter.com/... [image]
Kaspersky released a new blogpost today, documenting an iOS 0day + zero-click exploit used to target cybersecurity researchers. The scope and full victimology are still unknown. https://securelist.com/...