TriangleDB
MITRE ATT&CK: S1216 View on attack.mitre.org
Aliases: TriangleDB
- Malware type
- spyware, backdoor
- Family
- Malware family
- Operating systems
- ios
- Profile updated
- 2026-07-07 13:12:47
Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace
Context
TriangleDB is an Objective-C written implant deployed after Binary Validator and after root privileges are obtained during Operation Triangulation’s infection chain. Upon execution, TriangleDB communicates with the C2 server, relaying information about the victim device.
Detection coverage
- 1 YARA rules
Malware & tools used
- Ingress Tool Transfer (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- Out of Band Data (attack-pattern)
- Keychain (attack-pattern)
- File Deletion (attack-pattern)
- Software Discovery (attack-pattern)
- Location Tracking (attack-pattern)
- Process Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Data from Local System (attack-pattern)
Used by threat actors
- Operation Triangulation (campaign)
Detection rules
- SIGNATURE_BASE_APT_Equation_Group_Op_Triangulation_Triangledb_Implant_Jun23_1 (yara-rule)
Reports & references
- Kaspersky — 111669 (report)
- Kaspersky — 110916 (report)
- Kaspersky — 110847 (report)
- malpedia.caad.fkie.fraunhofer.de — Ios.Triangledb (report)
- media.ccc.de — 37C3 11859 Operation Triangulation What You Get When Attack Iphones Of Researchers (report)
- Kaspersky — 110050 (report)
- MITRE ATT&CK — S1216 (report)