logo

'Operation Triangulation' Spyware Attackers Bypass iPhone Memory Protections

ID: 8489d0d4-b2c4-51dc-ae1a-d55a720a86d5

STIX ID: report--8489d0d4-b2c4-51dc-ae1a-d55a720a86d5

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2023-12-29

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

Operation Triangulation is a highly sophisticated, multi-stage zero-click iMessage espionage campaign active since 2019 that exploits multiple iOS and kernel zero-days plus an undocumented Apple SoC hardware feature to bypass hardware memory protections and install TriangleDB spyware on targeted iPhones; Kaspersky GReAT detailed the attack chain, CVEs involved, affected targets (including diplomats and enterprises), and recommended mitigations such as disabling iMessage/FaceTime, applying iOS updates, and using EDR where possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.