Operation Triangulation: iOS devices targeted with previously unknown malware
securelist.com
securelist.com
This is an interesting way of phrasing “the OS is secure enough that even with full RCE and launching a separate binary, the attack cannot make itself survive a reboot”
Being non persistent also reduces your exposure on secondary payloads though. If I was a nation state with nearly unlimited resources, I would also monitor the mobile networks as well, which could give you a good idea when the jig is up.
Scan iPhone backups for traces of compromise by “Operation Triangulation” - https://news.ycombinator.com/item?id=36164340 - June 2023 (129 comments)
Targeted attack on our management with the Triangulation Trojan - https://news.ycombinator.com/item?id=36161392 - June 2023 (105 comments)
“Clickless” iOS exploits infect Kaspersky iPhones with never-before-seen malware - https://news.ycombinator.com/item?id=36154455 - June 2023 (38 comments)
Kaspersky Blog: “Triangulation” Attack on iOS - https://news.ycombinator.com/item?id=36154166 - June 2023 (4 comments)
This is a reminder to reboot your device if you haven't in a while. I have an app called iVerify, from Trail of Bits, which sends me periodic notifications reminding me to reboot or upgrade my OS.
Obviously not a good thing either way, but the most important part of this from the user perspective is whether or not up-to-date devices are vulnerable.
Additionally, I know this latest update did not happen on iOS 15 because (1) my phone did not receive an update, and (2) I am still seeing the sudden shut down and reboot activity when my battery is between 20-30% (as described by the webkit vulnerabilities as indication of an exploit).
However, according to Apple, iOS 16 is on 81% of all iPhones[2]. So I guess that means only 20% of mobile devices users are "targetable"? Lucky me...
Also, I will suggest that US Government officials NOT have older iPhones which do not support iOS 16. Seriously.
[1]https://securityaffairs.com/146411/security/apple-3-new-zero...
> Data usage information of the services com.apple.WebKit.WebContent, powerd/com.apple.datausage.diagnostics, lockdownd/com.apple.datausage.security
It's a bit baffling why you'd go after a antivirus company.
According to officials inside the Russian National Coordination Centre for Computer Incidents, the attacks were part of a broader campaign by the US National Security Agency that infected several thousand iPhones belonging to people inside diplomatic missions and embassies in Russia, specifically from those located in NATO countries, post-Soviet nations, Israel, and China. A separate alert from the FSB, Russia's Federal Security Service, alleged Apple cooperated with the NSA in the campaign. An Apple representative denied the claim.
https://arstechnica.com/information-technology/2023/06/click...
I'm surprised they use iPhone in those contexts. Specifically: I'm surprised that they allow usage of iPhone in such a context. Given how Russian intelligence perceives the US as its enemy, I would have guessed that using Apple devices would be banned entirely.
Yes to both.
Don't forget iOS 16 lockdown mode as well as a third option.
Ah but I'm glad Apple is at least focusing on the real issues, like blocking xhr and fetch requests over HTTP. facepalm