Researchers detail a zero-click iMessage attack that for over four years used four zero-days to hack iPhones, including dozens belonging to Kaspersky employees
“Triangulation” infected dozens of iPhones belonging to employees of Moscow-based Kaspersky. — Researchers on Wednesday …
Ars Technica Dan Goodin
Context & Ripple Effects
Triangulation had already prompted Apple patches for three exploited zero-days in June, after Kaspersky first reported the spyware activity. The later technical account turns that incident from a patch event into evidence of a sustained exploit chain.
It also fits a wider record of iPhone zero-click exploitation: Citizen Lab documented new zero-click iPhone hacks in 2022, while Project Zero tracked attackers reusing zero-days across major operating systems.
First-order effects
- Kaspersky and affected employees gain a fuller basis for incident assessment, because the disclosure identifies a four-zero-day chain operating over an extended period rather than an isolated iPhone flaw.
- Apple’s earlier fixes become part of a broader remediation record for Triangulation, while defenders can use the disclosed attack details to refine detection and device-review efforts.
Second-order effects
- The case raises the value of exploit-chain telemetry and forensic research for organizations whose mobile fleets may be targeted without user interaction.
- Other platform vendors and security teams face added pressure to shorten the interval between detecting active exploitation and shipping protections, especially for messaging-based attack paths.
Third-order effects
- If such long-lived chains continue to surface only after targeted investigations, mobile security will increasingly depend on specialist threat research as well as vendor patching.
- The pattern points toward a durable market for sophisticated zero-click capabilities, where the defensive challenge is not merely fixing individual bugs but disrupting multi-stage exploit development and deployment.
The trend: Triangulation is another data point in the persistence of high-end, zero-click mobile espionage chains that can remain effective until independent researchers and platform vendors expose them.
Related: Dual-use code intelligence · iPhones · Kaspersky · Apple patches three zero-days in macOS, iOS, iPadOS, and watchOS, expl · Citizen Lab: NSO Group deployed at least three new “zero-click” hacks
Related Coverage
- Operation Triangulation: The last (hardware) mystery Securelist · Boris Larin
- iPhone Triangulation attack abused undocumented hardware feature BleepingComputer · Bill Toulas
- iPhone 0-click spyware campaign ‘Triangulation’ detailed SC Media · Simon Hendery
- ‘Triangulation’ — Complex Exploit Backdoored Unknown Number of iPhones Over 4 Years Daring Fireball · John Gruber
- ‘Most sophisticated’ iPhone attack chain ‘ever seen’ used four 0-days to create a 0-click exploit 9to5Mac · Michael Potuck
- Security researcher Hector Martin weighs in on KTRR bypass findings iDownloadBlog.com · Anthony Bouchard
- Mysterious Apple SoC Feature Exploited to Hack Kaspersky Employee iPhones SecurityWeek · Ionut Arghire
- Four zero-day flaws are exploited as iPhone units are loaded with Spyware PhoneArena · Alan Friedman
- Lecture: Operation Triangulation: What You Get When Attack iPhones of Researchers Chaos Communication Congress
- Operation Triangulation: Undocumented iPhone hardware feature exposed SecurityBrief New Zealand · Shannon Williams
- Operation Triangulation: Previously unknown feature in iPhones exploited for spyware SiliconANGLE · Duncan Riley
- Operation Triangulation: The last (hardware) mystery — Very interesting iPhone vulnerability just dropped. … alluring heian courtesan · Eightyonekilograms
- Advanced Exploit Chain Affecting Older iOS Versions Detailed by Kaspersky Pixel Envy · Nick Heer
- Spyware attack chain used previously unknown iPhone hardware feature, report says The Record · Daryna Antoniuk
- Kaspersky team discusses how they discovered a KTRR bypass for arm64e devices at the 37c3 conference iDownloadBlog.com · Anthony Bouchard
- So some fun stuff was just presented at 37C3, and... I bet I have some answers. — https://securelist.com/... First, yeah, the dbgwrap stuff makes perfect sense. I knew about it for the main CPUs, makes perfect sense it'd exist for the ASCs too. Someone had a lightbulb moment. … @marcan@social.treehouse.systems · Hector Martin
- Kaspersky published technical details of exploits and vulnerabilities that were used in Operation Triangulation. The 0-click iMessage attack used four zero-days and was designed to work on iOS versions up to iOS 16.2. — CVE-2023-41990: A vulnerability in the ADJUST TrueType font instruction allowing remote code execution through a malicious iMessage attachment. … @simontsui@infosec.exchange · Simon
- Reminder, most of these exploits are not that advanced, are known for many years, and government agencies purposely hinder their remediation so they can be used for state sanctioned spying... 4-year campaign backdoored iPhones using possibly the most advanced exploit ever — https://arstechnica.com/... @devopscats@toot.cat
- this story about Kaspersky being infiltrated early and often via iOS 0days is wild! https://arstechnica.com/... more details: — https://securelist.com/... they even had validation services to ensure their exploit and implant didn't get jacked. hard not to admire this level of sophistication. … @emory@soc.kvet.ch · Emory L.
- If anyone is wondering why I stopped writing exploits, this graphic from @dangoodin's article on the Triangulation exploit chain sums it up: https://arstechnica.com/... Even the most difficult exploits I worked on rarely took more than a week. Modern exploit development is a different beast altogether. … @hdm@infosec.exchange · HD Moore
- although I have to say, @dangoodin is one of if not the best reporters at translating the gritty technical stuff, so it pays to always give his stuff a read too. without fail, he helps me increase my understanding @howelloneill@infosec.exchange · Patrick Howell O'Neill
- Some headlines are easy to imagine printed out and taped up in the offices where the exploits were developed https://arstechnica.com/... @howelloneill@infosec.exchange · Patrick Howell O'Neill
- A mass backdooring campaign reportedly infected iPhones of thousands of people working inside diplomatic missions and embassies in Russia. Over a span of at least four years, according to Kaspersky, the infections were delivered in iMessage texts that installed malware through a complex exploit chain without requiring the receiver to take any action. https://arstechnica.com/... @w7voa@journa.host · Steve Herman
- Researchers on Wednesday presented intriguing new findings surrounding an attack that over four years backdoored dozens if not thousands of iPhones, many of which belonged to employees of Moscow-based security firm Kaspersky. … @dangoodin@infosec.exchange · Dan Goodin
- somebody at the NSA is doing the ooops.gif face — https://www.bleepingcomputer.com/ ... @GossiTheDog@cyberplace.social · Kevin Beaumont
- Operation Triangulation: What you get when attack iPhones of researchers Hacker News
- 4-year campaign backdoored iPhones using advanced exploit Hacker News
- 4-Year Campaign Backdoored iPhones Using Possibly the Most Advanced Exploit Ever Slashdot · Msmash
- Exploit used in mass iPhone infection campaign targeted secret hardware feature Ars OpenForum
Discussion
-
@oct0xor
Boris Larin
on x
Jailbreak and kernel debugging is coming to new iPhones! (Apple A12-A16 SoC's < iOS 16.6) [image]
-
@evacide
Eva
on x
Security researchers presenting at CCC break down Triangulation, and it's full of juicy tidbits: https://securelist.com/...
-
@oct0xor
Boris Larin
on x
The recording of our (me, @bzvr_, @kucher1n) #37c3 talk “Operation Triangulation: What You Get When Attack iPhones of Researchers” was published! https://media.ccc.de/...
-
@itsclivetime
Clive Chan
on x
Four chained zero-days for a zero-click attack! Somebody somewhere has a massive bank of zero-days with an all-star team finding and chaining them together. Scary to think of the nested castles of sand we so deeply depend on.
-
@oct0xor
Boris Larin
on x
We're revealing details of an obscure debugging feature in the Apple A12-A16 SoC's that bypasses all of the hard-to-hack hardware-based memory protections on new iPhones. Its not used by the firmware and we don't know how the attackers found out about it. https://securelist.com/.…
-
@karpathy
Andrej Karpathy
on x
@itsclivetime What's fascinating to me is that the attacks, as sophisticated as they are, still make apparently silly and unnecessary mistakes (e.g. leaving strings around, see the video presentation), which then lead to the full reverse-engineering of them. Why so selectively br…
-
@karpathy
Andrej Karpathy
on x
“Operation Triangulation” https://securelist.com/... A newly discovered spyware campaign targeting Apple iPhone using a zero-click remote code execution via an attack chain of 4 zero-days, including highly mysterious, completely undocumented MMIO registers and hardware features..…
-
@rauchg
Guillermo Rauch
on x
Fascinating talk, highly recommended. The attackers used the hash of a WebGL rendered triangle for device fingerprinting 😲 [image]
-
@lukolejnik
@lukolejnik
on x
The Triangulation cyber espionage tool/malware turns out to be extremely advanced/fascinating. Certainly the ~most impressive piece in 2023, perhaps among the most impressive (known) cyber espionage tools in history? https://securelist.com/... [image]
-
@rmhrisk
Ryan Hurst
on x
This is a great example of how an attack chain comprised of sever vulnerabilities net a successful attack and why vendor rating of vulnerabilities in isolation of other potential vulnerabilities is a recipe for disaster.
-
@sweis
Steve Weis
on x
The talk mentions that the malware it dropped looks like it has existed for 10 years, collects everything, and uses Apple's client-side image recognition. [image]
-
@hackerfantastic
@hackerfantastic
on x
“We do not know how the attackers learned to use this unknown hardware feature or what its original purpose was. Neither do we know if it was developed by Apple or it's a third-party component like ARM CoreSight.” ... https://securelist.com/...
-
@sweis
Steve Weis
on x
This iMessage exploit is crazy. TrueType vulnerability that has existed since the 90s, 2 kernel exploits, a browser exploit, and an undocumented hardware feature that was not used in shipped software: https://securelist.com/... [image]
-
@alecmuffett
Alec Muffett
on x
iPhone Triangulation attack abused undocumented hardware feature | iPhones are “secure” except for the magic keys which are left underneath an undocumented doormat https://alecmuffett.com/...
-
@kucher1n
Georgy Kucherin
on x
Today, I will be giving a talk on Operation Triangulation with @oct0xor and @bzvr_ at #37c3 in Hamburg. Come see our talk if you are interested in learning more about this attack! [image]
-
@sourceloc
@sourceloc
on x
This will allow a jailbreak as powerful as palera1n (This is not a bootrom exploit). Huge