/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

The FSB claims Apple helped the NSA hack Russian diplomats' iPhones; Kaspersky: unknown malware leveraged zero-click exploits on iPhones running up to iOS 15.7

Russia's Federal Security Service (FSB) is accusing U.S. intelligence of hacking “thousands of Apple phones” to spy on Russian diplomats.

The Record Daryna Antoniuk

Context & Ripple Effects

The report combines an unverified state allegation against Apple with Kaspersky’s technical finding of malware using zero-click iPhone exploits. It lands in a documented pattern of sophisticated iPhone targeting: researchers had already identified new zero-click iPhone exploits affecting iOS 15 and early iOS 16.

The allegation also became consequential beyond the claimed intrusion itself: related coverage shows Russia later imposed a work-use ban on Apple devices for officials and state employees. Later research describing a long-running zero-click iMessage campaign affecting Kaspersky employees reinforces the importance of the underlying exploit risk, irrespective of attribution.

First-order effects

  • Apple faces a security and trust challenge in Russia, while the FSB’s claim puts the company at the center of an intelligence dispute it has not been shown to control.
  • Users on the affected iOS range face exposure to malware that requires no interaction, making patching and device-forensics capabilities immediately important for high-risk targets.

Second-order effects

  • Russian government organizations have a rationale to restrict Apple devices for work, shifting procurement and communications policies even though the FSB’s attribution remains an allegation.
  • The disclosure increases pressure on Apple and mobile-security researchers to identify and close zero-click attack paths, while making diplomatic and government users more likely to treat consumer phones as high-risk endpoints.

Third-order effects

  • If state agencies continue to tie mobile-device exploits to national-security claims, consumer device choice may increasingly be governed by sovereignty and trust considerations rather than product preferences alone.
  • The recurring discovery of zero-click iPhone chains points to a durable asymmetry: strong device security can reduce broad attacks, but well-resourced actors may still concentrate on a small number of high-value targets.

The trend: This is one data point in the growing securitization of smartphones, where zero-click vulnerabilities and contested attribution shape government technology policy.

Discussion

  • @kucher1n Georgy Kucherin on x
    Recently, I've been researching #OperationTriangulation, a very sophisticated campaign targeting iPhones of my colleagues. They have been infected (through zero-click exploits) with APT malware. Here are some results of our research: https://securelist.com/.... @bzvr_ @2igosha
  • @lorenzofb @lorenzofb on x
    UPDATE: Apple denies the accusations from the FSB: “We have never worked with any government to insert a backdoor into any Apple product and never will.” https://techcrunch.com/...
  • @lorenzofb @lorenzofb on x
    Another update: Kaspersky says it reached out to Apple this morning “before sending out the report to national CERTs.” In other worlds, they only reached out to Apple hours before they published the report. https://techcrunch.com/...
  • @cyb3rops Florian Roth on x
    A big advantage of a BYOD policy is that these devices use the orgs infra at some point & may create interesting log entries (DNS, proxy) Sigma Rules for - DNS logs - Proxy logs https://github.com/... #EquationGroup Reports https://securelist.com/... https://www-fsb-ru.translate.…
  • @kaspersky @kaspersky on x
    We've discovered a new cyberattack against iOS devices called Triangulation. The attack starts with an zero-click #iMessage with a malicious attachment which, using a number of vulnerabilities in iOS, installs spyware. #IOSTriangulation Full story 👇 https://securelist.com/...
  • @lorenzofb @lorenzofb on x
    We updated the story with details provided by Kaspersky spokesperson. All the company's answers are below. More interesting ones: -Several dozen employees allegedly hacked -No attribution -Some exploits may have been 0days -Discovered early 2023 https://techcrunch.com/... [image]
  • @josephfcox Joseph Cox on x
    New: Russia's FSB accuses US of hacking thousands of iPhones in Russia. Comes same day Kaspersky said someone targeted its own researchers' iPhones with sophisticated malware The indicators of compromise between the two are the same, Kaspersky noted to me https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    I asked Kaspersky if it had any coordination or communication with any parts of the Russian government regarding Kaspersky's announcement. This is what it said: ["When asked if Kaspersky had any coordination or communication with any parts of the Russian government regarding Kasp…
  • @staska Stasys Bielinis on x
    So that's how Biden knew Ukraine invasion was imminent in early 2022... It was Shoigu's or Gerasimov's iPhone! 😆 https://www.techmeme.com/...
  • @lorenzofb @lorenzofb on x
    NEW: Kaspersky says government hackers broke into the iPhones of several of its employees, using a zero-click exploit delivered via iMessage. At this point, there's no information on who was behind the attacks. https://techcrunch.com/...
  • @shakirov2036 Oleg Shakirov on x
    This type of accusations, which I refer to as quasi-attribution, are not unusual for Russian authorities. While somewhat specific, they lack technical detail For example in April, FSB accused U.S. & NATO of using Ukraine to launch cyber attacks on Russia https://twitter.com/...
  • @shakirov2036 Oleg Shakirov on x
    Kommersant also recalls that in March, staffers of the domestic politics branch of the Presidential Administration were told to stop using iPhones https://www.kommersant.ru/...
  • @1864memes @1864memes on x
    Why have you had to update all your devices so frequently this year? https://twitter.com/...
  • @bhadrapunchline M. K. Bhadrakumar on x
    Don't Indian elite use Apple phones as status symbol? They're screwed - being emperors without clothes, as NSA can get right inside their loin clothes & can smell it. Mother of all ironies is, US made our morons paranoid about Huawei. Aren't Arabs smarter? https://www.reuters.com…
  • @tr00perr @tr00perr on x
    So in other words, every IPhone on this planet is compromised and just waiting for that back door to be opened since it's apparent Apple hasn't secured this. https://twitter.com/... [image]
  • @justicerage Ivan Kwiatkowski on x
    Kaspersky released a new blogpost today, documenting an iOS 0day + zero-click exploit used to target cybersecurity researchers. The scope and full victimology are still unknown. https://securelist.com/...