/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers detail a zero-click iMessage attack that for over four years used four zero-days to hack iPhones, including dozens belonging to Kaspersky employees

“Triangulation” infected dozens of iPhones belonging to employees of Moscow-based Kaspersky.  —  Researchers on Wednesday …

Ars Technica Dan Goodin

Context & Ripple Effects

Triangulation had already prompted Apple patches for three exploited zero-days in June, after Kaspersky first reported the spyware activity. The later technical account turns that incident from a patch event into evidence of a sustained exploit chain.

It also fits a wider record of iPhone zero-click exploitation: Citizen Lab documented new zero-click iPhone hacks in 2022, while Project Zero tracked attackers reusing zero-days across major operating systems.

First-order effects

  • Kaspersky and affected employees gain a fuller basis for incident assessment, because the disclosure identifies a four-zero-day chain operating over an extended period rather than an isolated iPhone flaw.
  • Apple’s earlier fixes become part of a broader remediation record for Triangulation, while defenders can use the disclosed attack details to refine detection and device-review efforts.

Second-order effects

  • The case raises the value of exploit-chain telemetry and forensic research for organizations whose mobile fleets may be targeted without user interaction.
  • Other platform vendors and security teams face added pressure to shorten the interval between detecting active exploitation and shipping protections, especially for messaging-based attack paths.

Third-order effects

  • If such long-lived chains continue to surface only after targeted investigations, mobile security will increasingly depend on specialist threat research as well as vendor patching.
  • The pattern points toward a durable market for sophisticated zero-click capabilities, where the defensive challenge is not merely fixing individual bugs but disrupting multi-stage exploit development and deployment.

The trend: Triangulation is another data point in the persistence of high-end, zero-click mobile espionage chains that can remain effective until independent researchers and platform vendors expose them.

Discussion

  • @oct0xor Boris Larin on x
    Jailbreak and kernel debugging is coming to new iPhones! (Apple A12-A16 SoC's < iOS 16.6) [image]
  • @evacide Eva on x
    Security researchers presenting at CCC break down Triangulation, and it's full of juicy tidbits: https://securelist.com/...
  • @oct0xor Boris Larin on x
    The recording of our (me, @bzvr_, @kucher1n) #37c3 talk “Operation Triangulation: What You Get When Attack iPhones of Researchers” was published! https://media.ccc.de/...
  • @itsclivetime Clive Chan on x
    Four chained zero-days for a zero-click attack! Somebody somewhere has a massive bank of zero-days with an all-star team finding and chaining them together. Scary to think of the nested castles of sand we so deeply depend on.
  • @oct0xor Boris Larin on x
    We're revealing details of an obscure debugging feature in the Apple A12-A16 SoC's that bypasses all of the hard-to-hack hardware-based memory protections on new iPhones. Its not used by the firmware and we don't know how the attackers found out about it. https://securelist.com/.…
  • @karpathy Andrej Karpathy on x
    @itsclivetime What's fascinating to me is that the attacks, as sophisticated as they are, still make apparently silly and unnecessary mistakes (e.g. leaving strings around, see the video presentation), which then lead to the full reverse-engineering of them. Why so selectively br…
  • @karpathy Andrej Karpathy on x
    “Operation Triangulation” https://securelist.com/... A newly discovered spyware campaign targeting Apple iPhone using a zero-click remote code execution via an attack chain of 4 zero-days, including highly mysterious, completely undocumented MMIO registers and hardware features..…
  • @rauchg Guillermo Rauch on x
    Fascinating talk, highly recommended. The attackers used the hash of a WebGL rendered triangle for device fingerprinting 😲 [image]
  • @lukolejnik @lukolejnik on x
    The Triangulation cyber espionage tool/malware turns out to be extremely advanced/fascinating. Certainly the ~most impressive piece in 2023, perhaps among the most impressive (known) cyber espionage tools in history? https://securelist.com/... [image]
  • @rmhrisk Ryan Hurst on x
    This is a great example of how an attack chain comprised of sever vulnerabilities net a successful attack and why vendor rating of vulnerabilities in isolation of other potential vulnerabilities is a recipe for disaster.
  • @sweis Steve Weis on x
    The talk mentions that the malware it dropped looks like it has existed for 10 years, collects everything, and uses Apple's client-side image recognition. [image]
  • @hackerfantastic @hackerfantastic on x
    “We do not know how the attackers learned to use this unknown hardware feature or what its original purpose was. Neither do we know if it was developed by Apple or it's a third-party component like ARM CoreSight.” ... https://securelist.com/...
  • @sweis Steve Weis on x
    This iMessage exploit is crazy. TrueType vulnerability that has existed since the 90s, 2 kernel exploits, a browser exploit, and an undocumented hardware feature that was not used in shipped software: https://securelist.com/... [image]
  • @alecmuffett Alec Muffett on x
    iPhone Triangulation attack abused undocumented hardware feature | iPhones are “secure” except for the magic keys which are left underneath an undocumented doormat https://alecmuffett.com/...
  • @kucher1n Georgy Kucherin on x
    Today, I will be giving a talk on Operation Triangulation with @oct0xor and @bzvr_ at #37c3 in Hamburg. Come see our talk if you are interested in learning more about this attack! [image]
  • @sourceloc @sourceloc on x
    This will allow a jailbreak as powerful as palera1n (This is not a bootrom exploit). Huge