TriangleDB is a sophisticated iOS backdoor first publicly documented by Kaspersky in June 2023 as part of Operation Triangulation, a long-running espionage campaign attributed to an advanced persistent threat (APT) group linked to the Russian Federation. It belongs to the spyware category and is deployed exclusively on compromised Apple iOS devices via a zero-click exploit chain targeting unknown vulnerabilities.
TriangleDB propagates through malicious iMessage attachments exploiting four zero-day vulnerabilities: CVE-2023-32434 (kernel), CVE-2023-32435 (JavaScriptCore), CVE-2023-32439 (WebKit), and CVE-2023-38606 (kernel). The malware establishes a command-and-control (C2) infrastructure over HTTPS using a custom protocol, employing domain fronting to evade network detection. Persistence is achieved through a Launch Daemon injected into the system, while evasion techniques include runtime integrity checks, anti-debugging with ptrace, and encryption of communication payloads. The backdoor grants full remote access including microphone, camera, GPS, and filesystem exfiltration and can execute arbitrary commands with root privileges via a Mach-O binary.
First detected in May 2023 on Kaspersky employee devices, TriangleDB infected at least 50 iOS devices across multiple countries including Russia, China, and Germany. The initial attack vector exploited an undocumented hardware feature in Apple’s SoC design (later tied to CVE-2023-38606) allowing bypass of kernel memory protections. No law enforcement actions have been publicly reported, and the campaign remained active through 2024 according to Kaspersky’s follow-up analysis.
Known file hashes include SHA256 9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f9f (example placeholder; actual hashes published in Kaspersky advisory). Behavioral signatures include unexpected high CPU usage from the launchd process, abnormal iMessage activity with no visible messages, and network connections to domains like cpanel.icloud-content.com and setup.icloud.com used for C2. No specific registry keys or mutex names apply to iOS; analysis relies on sysdiagnose logs and network IOCs.
TriangleDB poses extreme risk due to its zero-click delivery and full device compromise, enabling complete data exfiltration including encrypted app data, credentials, and real-time surveillance. The campaign has primarily targeted individuals in diplomatic, government, and technology sectors within Eastern Europe and Central Asia. No direct financial losses have been publicized, but the intelligence-gathering impact is assessed as high.
Apple released patches for all exploited CVEs in iOS 16.5.1 and iOS 15.7.7 in June 2023; devices must update immediately. Recommended defenses include enabling Lockdown Mode (which blocks iMessage zero-click attacks), deploying endpoint detection rules for anomalous iMessage behavior, and monitoring network logs for connections to known C2 domains listed in Kaspersky’s security advisory.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.