bk99.de entertain the web since 1997

Operation Triangulation: Five vulnerabilities to iPhone surveillance

Summary

oct0xor, kucher1n and bzvr_ reconstruct a multi-stage iOS zero-click chain that combined four zero-days and an undocumented hardware feature. The chain used five vulnerabilities, four of them zero-days. The analysis led to fixes for four previously unknown vulnerabilities.

Ideas

  • A manipulated iMessage started the attack chain without any action by the victim.
  • Several exploits overcame parser, sandbox, kernel and hardware protection one after another.
  • Undocumented processor features can give attackers unknown capabilities.
  • The researchers’ own affected devices made it possible to record every stage of the attack.
  • Years of stealth require careful telemetry and independent forensic tools.
  • A complete exploit path is more valuable than looking at individual vulnerabilities in isolation.

Insights

  • Platform integration increases both defensive strength and the possible depth of chaining.
  • Undocumented hardware undermines public scrutiny even when the operating system code is well researched.
  • An attack on researchers can unintentionally expose its entire toolchain.

Quotes

  • This is the story of the most sophisticated attack chain and spyware ever discovered by Kaspersky. – talk description

Habits

  • The team secured infected devices and analysed each stage separately over several months.

References

  • CCC: Operation Triangulation
  • Kaspersky: employer of the affected researchers and publishing organisation.
  • iMessage and WebKit: early stages of the attack chain.

Critique

  • Kaspersky’s superlative about the complexity is its own assessment and not an objective ranking.
  • The presentation could not conclusively explain the origin and purpose of the undocumented hardware feature.

Remarks

  • The talk documents an unusually large number of stages of a zero-click chain used in the wild.
  • The earliest traces of the campaign found went back several years.

Recommendations

  • Separate high-risk communication from particularly valuable administrative access.
  • Collect mobile network and system indicators sparingly for forensic comparison.
  • Update mobile operating systems promptly and replace devices that no longer receive updates.

Watch the talk

Search the Web Archive