Evil Eye Threat Actor Resurfaces with iOS Exploit and Updated Implant
ID: 2e4af036-96b8-5609-8d58-2deded5b3413
STIX ID: report--2e4af036-96b8-5609-8d58-2deded5b3413
Feed Name: Volexity Blog
Volexity documents a targeted campaign by the Evil Eye APT leveraging IRONSQUIRREL-based web exploits on compromised Uyghur websites to deliver an iOS root implant called INSOMNIA against devices running iOS 12.3–12.3.2; the implant (written to /tmp/updateserver) collects and exfiltrates app and messaging data (including Signal and ProtonMail artefacts), validates C2 via embedded certificates, and communicates over HTTPS to multiple hard-coded C2 IPs and hostnames, with several IOCs and SHA256 hashes provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
