Operation Triangulation: Five vulnerabilities to iPhone surveillance
Summary
oct0xor, kucher1n and bzvr_ reconstruct a multi-stage iOS zero-click chain that combined four zero-days and an undocumented hardware feature. The chain used five vulnerabilities, four of them zero-days. The analysis led to fixes for four previously unknown vulnerabilities.
Ideas
- A manipulated iMessage started the attack chain without any action by the victim.
- Several exploits overcame parser, sandbox, kernel and hardware protection one after another.
- Undocumented processor features can give attackers unknown capabilities.
- The researchers’ own affected devices made it possible to record every stage of the attack.
- Years of stealth require careful telemetry and independent forensic tools.
- A complete exploit path is more valuable than looking at individual vulnerabilities in isolation.
Insights
- Platform integration increases both defensive strength and the possible depth of chaining.
- Undocumented hardware undermines public scrutiny even when the operating system code is well researched.
- An attack on researchers can unintentionally expose its entire toolchain.
Quotes
This is the story of the most sophisticated attack chain and spyware ever discovered by Kaspersky.
– talk description
Habits
- The team secured infected devices and analysed each stage separately over several months.
References
- CCC: Operation Triangulation
- Kaspersky: employer of the affected researchers and publishing organisation.
- iMessage and WebKit: early stages of the attack chain.
Critique
- Kaspersky’s superlative about the complexity is its own assessment and not an objective ranking.
- The presentation could not conclusively explain the origin and purpose of the undocumented hardware feature.
Remarks
- The talk documents an unusually large number of stages of a zero-click chain used in the wild.
- The earliest traces of the campaign found went back several years.
Recommendations
- Separate high-risk communication from particularly valuable administrative access.
- Collect mobile network and system indicators sparingly for forensic comparison.
- Update mobile operating systems promptly and replace devices that no longer receive updates.
Links to the original source and the Web Archive open in a new tab.