s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ios.triangledb

📛 Threat Title

Malware family: TriangleDB

Category: TriangleDB First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ios.triangledb`. Printable name: TriangleDB.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ios.triangledb VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.triangledb

IOC database

Type
domain
Value
ios.triangledb
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ios.triangledb

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.triangledb

References (1)

Remediations (10)

  • web:attack.mitre.org

    TriangleDB is an Objective-C written implant deployed after Binary Validator and after root privileges are obtained during Operation Triangulation 's infection chain. Upon execution, TriangleDB communicates with the C2 server, relaying information about the victim device. [1]

  • web:blog.netmanageit.com

    Intelligence Report Dissecting TriangleDB , a Triangulation spyware implant Table of contents ... Overview Description An in-depth analysis of a spyware implant developed by attackers using an exploit known as Operation Triangulation to infect iOS devices in the next 20th Century, and how it is deployed.

  • web:en.wikipedia.org

    The TriangleDB malware has a modular structure, so its functions can be extended by downloading additional modules from the server. The basic version can upload files from the device to the attackers' server, extract data from the keychain, track the victim's geolocation, and modify files and processes on the smartphone.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the TriangleDB malware family including references, samples and yara signatures.

  • web:malwaretips.com

    Whoever is infecting people's iPhones with the TriangleDB spyware may be targeting macOS computers with similar malware , according to Kaspersky researchers. In the security shop's ongoing analysis of the smartphone snooping campaign - during which attackers exploit a kernel vulnerability to obtain root privileges and install TriangleDB on victims' handsets - Kaspersky analysts uncovered 24 ...

  • web:securelist.com

    In researching Operation Triangulation, we set ourselves the goal to retrieve as many parts of the exploitation chain as possible. As of now, we have finished analyzing the spyware implant and are ready to share the details.

  • web:securityaffairs.com

    Kaspersky provided more details about Operation Triangulation, including the exploitation chain and the implant used by the threat actors.

  • web:securityparrot.com

    The malicious implant, called TriangleDB , is used to collect victims' data and runs exclusively in the memory of the iOS device, deleting its traces upon reboot. Kaspersky Lab researchers have now presented a detailed report on the TriangleDB malware written in Objective-C.

  • web:www.cybersecurity-review.com

    News June 2023 Tags Apple, APT, CNE, CNO, Cyber Espionage, Data Collection, iOS, Malware Analysis, Spyware, Surveillance, Threat Intelligence, TriangleDB , Triangulation, TTPs, Zero-Click exploit ← Previous

  • web:www.kaspersky.com

    In addition, our solution provides protection against phishing, web threats and malware (for Android only; Apple doesn't allow third-party antivirus solutions unfortunately). In particular, it employs Cloud ML for Android technology to detect Android-related malware . This technology, working in KSN cloud, is based on machine learning methods.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.