TF-MAL-ios.triangledb
📛 Threat Title
Malware family: TriangleDB
Description
ThreatFox malware family `ios.triangledb`. Printable name: TriangleDB.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ios.triangledb
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.triangledb
IOC database
- Type
- domain
- Value
ios.triangledb- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ios.triangledb
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ios.triangledb
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
TriangleDB is an Objective-C written implant deployed after Binary Validator and after root privileges are obtained during Operation Triangulation 's infection chain. Upon execution, TriangleDB communicates with the C2 server, relaying information about the victim device. [1]
-
web:blog.netmanageit.com
Intelligence Report Dissecting TriangleDB , a Triangulation spyware implant Table of contents ... Overview Description An in-depth analysis of a spyware implant developed by attackers using an exploit known as Operation Triangulation to infect iOS devices in the next 20th Century, and how it is deployed.
-
web:en.wikipedia.org
The TriangleDB malware has a modular structure, so its functions can be extended by downloading additional modules from the server. The basic version can upload files from the device to the attackers' server, extract data from the keychain, track the victim's geolocation, and modify files and processes on the smartphone.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the TriangleDB malware family including references, samples and yara signatures.
-
web:malwaretips.com
Whoever is infecting people's iPhones with the TriangleDB spyware may be targeting macOS computers with similar malware , according to Kaspersky researchers. In the security shop's ongoing analysis of the smartphone snooping campaign - during which attackers exploit a kernel vulnerability to obtain root privileges and install TriangleDB on victims' handsets - Kaspersky analysts uncovered 24 ...
-
web:securelist.com
In researching Operation Triangulation, we set ourselves the goal to retrieve as many parts of the exploitation chain as possible. As of now, we have finished analyzing the spyware implant and are ready to share the details.
-
web:securityaffairs.com
Kaspersky provided more details about Operation Triangulation, including the exploitation chain and the implant used by the threat actors.
-
web:securityparrot.com
The malicious implant, called TriangleDB , is used to collect victims' data and runs exclusively in the memory of the iOS device, deleting its traces upon reboot. Kaspersky Lab researchers have now presented a detailed report on the TriangleDB malware written in Objective-C.
-
web:www.cybersecurity-review.com
News June 2023 Tags Apple, APT, CNE, CNO, Cyber Espionage, Data Collection, iOS, Malware Analysis, Spyware, Surveillance, Threat Intelligence, TriangleDB , Triangulation, TTPs, Zero-Click exploit ← Previous
-
web:www.kaspersky.com
In addition, our solution provides protection against phishing, web threats and malware (for Android only; Apple doesn't allow third-party antivirus solutions unfortunately). In particular, it employs Cloud ML for Android technology to detect Android-related malware . This technology, working in KSN cloud, is based on machine learning methods.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.