Binary Validator

MITRE ATT&CK: S1215 View on attack.mitre.org

Aliases: Binary Validator

First seen
2023-06-01 00:00:00
Malware type
dropper, spyware
Family
Malware family
Operating systems
ios
Profile updated
2026-07-07 13:12:49

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Binary Validator is a Mach-O binary file used during Operation Triangulation. Binary Validator first collects information about the device, such as the device's phone number and a list of installed applications, before the deployment of the TriangleDB implant. After the actions are completed and the data is collected, Binary Validator encrypts and sends the data to the C2 server, and in turn, the C2 server sends the TriangleDB implant.

Malware & tools used

  • Execution Guardrails (attack-pattern)
  • Software Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)

Used by threat actors

  • Operation Triangulation (campaign)

Reports & references

  • Kaspersky — 110847 (report)
  • MITRE ATT&CK — S1215 (report)

External references