TriangleDB

Malware

⚠️ Overview

TriangleDB is a sophisticated iOS backdoor first publicly documented by Kaspersky in June 2023 as part of Operation Triangulation, a long-running espionage campaign attributed to an advanced persistent threat (APT) group linked to the Russian Federation. It belongs to the spyware category and is deployed exclusively on compromised Apple iOS devices via a zero-click exploit chain targeting unknown vulnerabilities.

🔧 Technical Capabilities

TriangleDB propagates through malicious iMessage attachments exploiting four zero-day vulnerabilities: CVE-2023-32434 (kernel), CVE-2023-32435 (JavaScriptCore), CVE-2023-32439 (WebKit), and CVE-2023-38606 (kernel). The malware establishes a command-and-control (C2) infrastructure over HTTPS using a custom protocol, employing domain fronting to evade network detection. Persistence is achieved through a Launch Daemon injected into the system, while evasion techniques include runtime integrity checks, anti-debugging with ptrace, and encryption of communication payloads. The backdoor grants full remote access including microphone, camera, GPS, and filesystem exfiltration and can execute arbitrary commands with root privileges via a Mach-O binary.

📜 History & Notable Incidents

First detected in May 2023 on Kaspersky employee devices, TriangleDB infected at least 50 iOS devices across multiple countries including Russia, China, and Germany. The initial attack vector exploited an undocumented hardware feature in Apple’s SoC design (later tied to CVE-2023-38606) allowing bypass of kernel memory protections. No law enforcement actions have been publicly reported, and the campaign remained active through 2024 according to Kaspersky’s follow-up analysis.

🔍 Detection Indicators

Known file hashes include SHA256 9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f (example placeholder; actual hashes published in Kaspersky advisory). Behavioral signatures include unexpected high CPU usage from the launchd process, abnormal iMessage activity with no visible messages, and network connections to domains like cpanel.icloud-content.com and setup.icloud.com used for C2. No specific registry keys or mutex names apply to iOS; analysis relies on sysdiagnose logs and network IOCs.

☠️ Risk & Impact

TriangleDB poses extreme risk due to its zero-click delivery and full device compromise, enabling complete data exfiltration including encrypted app data, credentials, and real-time surveillance. The campaign has primarily targeted individuals in diplomatic, government, and technology sectors within Eastern Europe and Central Asia. No direct financial losses have been publicized, but the intelligence-gathering impact is assessed as high.

🛡️ Mitigation

Apple released patches for all exploited CVEs in iOS 16.5.1 and iOS 15.7.7 in June 2023; devices must update immediately. Recommended defenses include enabling Lockdown Mode (which blocks iMessage zero-click attacks), deploying endpoint detection rules for anomalous iMessage behavior, and monitoring network logs for connections to known C2 domains listed in Kaspersky’s security advisory.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.