Live data from Hacker News

Targeted attack on our management with the Triangulation Trojan

usa.kaspersky.com

71–80 of 131 posts

Re: Targeted attack on our management with the Triangulation Trojan

#72
post #61

Earlier quoted context omitted.

Or you live in Russia and you thought you had a deal that NATO wouldn't encroach further on your border... It was a trick question, none of them are good.

Unlike you, I actually lived in Russia and I can tell with 100% certainty that it's a bs narrative that was used to build up Putin support based on confrontation with the "west".

So no agreements had previously been made then?

https://nsarchive.gwu.edu/briefing-book/russia-programs/2017...

I mean, I'm not supporting Russia's actions here, I'm saying the US (mainly) are just a bad an actor. They're essentially fighting a war with Russia (as their warmongers and military complex love to tell their shareholders about), Ukraine is just the pawn in the middle.

I should have said 'towards' the border, not 'on.' My bad.

Re: Targeted attack on our management with the Triangulation Trojan

#73

tl;dr - malicious state and private threat actors can at any time completely take over your iphone (root access) with an invisible iMessage without you having a practical chance to detect it besides scanning your iphone backup

It still blows my mind that this is not a known fact by most people for as long as phones have existed? Or maybe it is?

how is this generally possible? In my simplified understanding, a text message is a hunk of data, but I know it's more complex than that.... it must be able to connect to all kinds of services and trigger all kinds of code running, right? Can't it be sanity checked sufficiently?

Re: Targeted attack on our management with the Triangulation Trojan

#74
post #10

From the article > We believe that the main reason for this incident is the proprietary nature of iOS. This operating system is a “black box”, in which spyware like Triangulation can hide for years. Detecting and analyzing such threats is made all the more difficult by Apple’s monopoly of research tools – making it a perfect haven for spyware. In other words, as I’ve often said, users are given the illusion of securi…

Why are top management at Kaspersky using iPhones, presumably they knew iPhones were a “black box” and a security risk.

Eh, of course they did. It almost almost sounds like a honeypot, even. I think there is more to this than they're saying for now.

Re: Targeted attack on our management with the Triangulation Trojan

#75
post #69

Earlier quoted context omitted.

Right you can turn off getting any messages entirely and deregister your phone from their network. I believe what I was remembering was you can't swap out the primary SMS receiving app like you can on Android. Unless something changed. Not everyone like's to live in a security bubble w/o phone access, even the security minded.

There is a switch in the Settings app to disable iMessage and just use SMS. This is an option for the built in messaging app, no need to “swap” or install another app.

So basically still using iMessage software just for SMS? I guess this could provide some better sense of security given the parsers are the main issue.

Re: Targeted attack on our management with the Triangulation Trojan

#77

Earlier quoted context omitted.

Shatters Apple's argument that all of these hurdles are better for security. I wonder if testimony like this could affect any of their antitrust lawsuits or right to repair lobbying.

It reads more like an excuse than the actual reason. Endpoint protection solutions can be installed in iOS devices. The device could also be wiped clean, eliminating the malware. The latter should not be much of an issue in any serious organization. If any executive keeps critical data in a phone, that is already an issue. The former is a hassle, but I have had to use locked down iPhones before, and the tradeoffs are…

I'm very happy Kaspersky has. And that their released a tool they believe can detect past and present infection with the Triangulation Trojan.

I've not idea to what extent it's possible to have a durable trojan on iOS (probably only the makers of such trojans do know).

It's absurd to say a company should not blow the whistle on a sophisticated attack when that companys job is just that!

Re: Targeted attack on our management with the Triangulation Trojan

#78
post #61

Earlier quoted context omitted.

Unlike you, I actually lived in Russia and I can tell with 100% certainty that it's a bs narrative that was used to build up Putin support based on confrontation with the "west".

So no agreements had previously been made then? https://nsarchive.gwu.edu/briefing-book/russia-programs/2017... I mean, I'm not supporting Russia's actions here, I'm saying the US (mainly) are just a bad an actor. They're essentially fighting a war with Russia (as their warmongers and military complex love to tell their shareholders about), Ukraine is just the pawn in the middle. I should have said 'towards' the bord…

You are twisting the history. It was russia that attacked Ukraine in 2014 and occupied Crimea and half of Donetsk and Luhansk regions without any slightest provocation from Ukraine side. 2022 invasion is merely an episode in this war that goes for 9 years already.

Re: Targeted attack on our management with the Triangulation Trojan

#79
post #44

"An indirect indication of the presence of Triangulation on the device is the disabling of the ability to update iOS" My guess would be that they didn't find out thanks to their monitoring solution, but because some senior manager shouted pretty loudly at someone to get their iPhone to update, asap! :)

Or maybe the monitoring solution noticed the LACK of update checks from iOS devices.

Noticed a lack of updates after 6 months. The whole thing doesn't exactly speak to extreme infosec competence at Kaspersky labs in my opinion.

Re: Targeted attack on our management with the Triangulation Trojan

#80

tl;dr - malicious state and private threat actors can at any time completely take over your iphone (root access) with an invisible iMessage without you having a practical chance to detect it besides scanning your iphone backup

Should add that this can only occur if you haven't updated your phone in over a year.

They said it can infect iOS 15.7. I just looked and it appears 15.7.1 was released 10/27/22. And the malware apparently quietly blocks OS updates and can survive full hardware resets.

If you were fully updated to the latest iOS last October and got infected, it would keep you infected. They also said they found the malware has been deployed in the wild since at least 2019 and this is the first discovery o. f it. And it appears to be a fully remote, stealth infection against all iPhones.

I'm no expert on security (or iOS) but it sounds pretty much like worst case to me.

Post reply on HN