Live data from Hacker News

Targeted attack on our management with the Triangulation Trojan

usa.kaspersky.com

51–60 of 131 posts

Re: Targeted attack on our management with the Triangulation Trojan

#51
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Why are top management at Kaspersky using iPhones, presumably they knew iPhones were a “black box” and a security risk.

Why are they running iMessage? That’s the real vector here.

Re: Targeted attack on our management with the Triangulation Trojan

#52

> What actually happens in iOS is unknown to cybersecurity experts Sounds like a skill issue to me. I'll eat my words if they were genuinely infected with something that lingered in such a way that it persisted past a reboot and completely broke all updates, but I would be very surprised if this was the case.

Why would an actor with a reliable zero-click need to persist past a reboot? That appears to be the claim in the article, update blocking plus on-demand reinfection.

Re: Targeted attack on our management with the Triangulation Trojan

#53
post #22
post #17

Earlier quoted context omitted.

Why are they using iOS if they feel that way about it? Also: iOS 16 is not vulnerable and it was released on September 12, 2022 - why are those phones out of date for so long?

Does an OS upgrade remove this malware though? Maybe it doesn't and it's why so many phones were infected.

Latest update from Kaspersky.

> June 02 2023 Update: triangle_check utility

> We have developed and made freely available the triangle_check utility, that can detect indicators of compromise in an Apple device backup. Detailed instructions on how to use it under different OSs (Windows, Linux and macOS), as well as how to create a device backup can be found in a post on Securelist. [1]

[1]: https://securelist.com/find-the-triangulation-utility/109867...

Re: Targeted attack on our management with the Triangulation Trojan

#54
post #42

Earlier quoted context omitted.

I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.

Or you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border... It was a trick question, none of them are good.

Soviet Union asked to join NATO but was rejected, and the post-Soviet Russian Federation started on the path to joining back in the day.

It's not NATO's fault that all the small countries around Russia are so scared of Russian forces that they all ask to join a mutual defence pact.

Re: Targeted attack on our management with the Triangulation Trojan

#55
post #42

Earlier quoted context omitted.

I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.

Or you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border... It was a trick question, none of them are good.

Has NATO crossed any Russian border?

Now nearing borders appears motivated more by Russia's bullying of its neighbors than any desire within NATO to expand.

Maybe you're forgetting the protection treaty Russia signed to respect Ukraine's borders in exchange for USSR nukes.

Re: Targeted attack on our management with the Triangulation Trojan

#56
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Why are top management at Kaspersky using iPhones, presumably they knew iPhones were a “black box” and a security risk.

What should they be using instead?

Re: Targeted attack on our management with the Triangulation Trojan

#57
post #19

Earlier quoted context omitted.

Of course it is like this. We live in the golden age of cyberwars. But you as a founder decide whose values of the surrounding society you align your company with. In an autocratic nation these controls are kind of absolutist in nature, whereas in democracies you have at least some sense of oversight. Given the mechanics of the game, where you reside your company tells a lot about who you're friends with. These days…

> whereas in democracies you have at least some sense of oversight Can you give some examples of oversight ?

https://en.wikipedia.org/wiki/United_States_Intelligence_Com...

Re: Targeted attack on our management with the Triangulation Trojan

#58
post #42

Earlier quoted context omitted.

I mean, unless you live in Middle East and one day they say you have WMD and they destroy your whole country. If you live in the EU or the US - then yes.

Or you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border... It was a trick question, none of them are good.

For your statement to make sense, Russia's borders would have to start at Ukraine's borders, which they do not.

Re: Targeted attack on our management with the Triangulation Trojan

#59
post #44

"An indirect indication of the presence of Triangulation on the device is the disabling of the ability to update iOS" My guess would be that they didn't find out thanks to their monitoring solution, but because some senior manager shouted pretty loudly at someone to get their iPhone to update, asap! :)

Or maybe the monitoring solution noticed the LACK of update checks from iOS devices.

Re: Targeted attack on our management with the Triangulation Trojan

#60
post #17
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Why are they using iOS if they feel that way about it? Also: iOS 16 is not vulnerable and it was released on September 12, 2022 - why are those phones out of date for so long?

From the comments section on Securelist page on Operation Triangulation https://securelist.com/operation-triangulation/109842/

> SECURELIST

> Posted on June 2, 2023. 11:10 am

> Hi Bil!

> We identified that the latest version of iOS that was targeted by Triangulation is 15.7. However, given the sophistication of the cyberespionage campaign and the complexity of analysis of iOS platform, we can’t guarantee that other versions of iOS are not affected.

Post reply on HN