TriangleDB

MITRE ATT&CK: S1216 View on attack.mitre.org

Aliases: TriangleDB

Malware type
spyware, backdoor
Family
Malware family
Operating systems
ios
Profile updated
2026-07-07 13:12:47

Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace

Context

TriangleDB is an Objective-C written implant deployed after Binary Validator and after root privileges are obtained during Operation Triangulation’s infection chain. Upon execution, TriangleDB communicates with the C2 server, relaying information about the victim device.

Detection coverage

  • 1 YARA rules

Malware & tools used

  • Ingress Tool Transfer (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • Out of Band Data (attack-pattern)
  • Keychain (attack-pattern)
  • File Deletion (attack-pattern)
  • Software Discovery (attack-pattern)
  • Location Tracking (attack-pattern)
  • Process Discovery (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Data from Local System (attack-pattern)

Used by threat actors

  • Operation Triangulation (campaign)

Detection rules

  • SIGNATURE_BASE_APT_Equation_Group_Op_Triangulation_Triangledb_Implant_Jun23_1 (yara-rule)

Reports & references

  • Kaspersky — 111669 (report)
  • Kaspersky — 110916 (report)
  • Kaspersky — 110847 (report)
  • malpedia.caad.fkie.fraunhofer.de — Ios.Triangledb (report)
  • media.ccc.de — 37C3 11859 Operation Triangulation What You Get When Attack Iphones Of Researchers (report)
  • Kaspersky — 110050 (report)
  • MITRE ATT&CK — S1216 (report)

External references