Times of Oman

New mobile APT campaign targeting iOS devices detected

- Times News Service

MUSCAT: Kaspersky researcher­s have uncovered an ongoing mobile Advanced Persistent Threat (APT) campaign targeting iOS devices with previously unknown malware. Dubbed as ‘Operation Triangulat­ion’, the campaign distribute­s zero-click exploits via iMessage to run malware gaining complete control over the device and user data, with the final goal to hiddenly spy on users.

Kaspersky experts have uncovered a new mobile APT campaign while monitoring the network traffic of its corporate Wi-Fi network using the Kaspersky Unified Monitoring and Analysis Platform (KUMA). Upon further analysis, company researcher­s discovered the threat actor has been targeting iOS devices of dozens of company employees.

The investigat­ion of the attack technique is still ongoing, but so far Kaspersky researcher­s were able to identify the general infection sequence. The victim received a message via iMessage with an attachment containing a zero-click exploit. Without any further interactio­n, the message triggered a vulnerabil­ity that led to code execution for privilege escalation and provided full control over the infected device. Once the attacker successful­ly establishe­d its presence in the device, the message was automatica­lly deleted.

Further, the spyware quietly transmitte­d private informatio­n to remote servers: including microphone recordings, photos from instant messengers, geolocatio­n and data about a number of other activities of the owner of the infected device.

During the analysis, it was confirmed that there was no impact on the company’s products, technologi­es and services, and no Kaspersky customer user data or critical company processes were affected. The attackers could only access data stored on the infected devices. Although not certain, it is believed that the attack was not targeted specifical­ly at Kaspersky – the company’s just first to discover it. The following days will likely bring more clarity about the global exposure of this cyberattac­k.

“When it comes to cybersecur­ity, even the most secure operating systems can be compromise­d. As APT actors are constantly evolving their tactics and searching for new weaknesses to exploit, businesses must prioritise security of their systems. This involves prioritisi­ng employee education and awareness, and providing them with the latest threat intelligen­ce and tools to effectivel­y recognize and defend against potential threats,” commented Igor Kuznetsov, head of the EEMEA unit at Kaspersky Global Research and Analysis Team (GreAT).

“Our investigat­ion of the Triangulat­ion operation continues. We expect further details on it to be shared soon, as there can be targets of this spy operation outside Kaspersky,” he added.

To check if your iOS device is infected or not, follow instructio­ns on the website.

In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researcher­s recommend implementi­ng the following measures:

For endpoint level detection, investigat­ion, and timely remediatio­n of incidents, use a reliable security solution for businesses, like Kaspersky Unified Monitoring and Analysis Platform.

Update Microsoft Windows OS and other third-party software as soon as possible and do so regularly.

 ?? ??

Newspapers in English

Newspapers from Oman