Operation Triangulation
- First seen
- 2019-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:13:45
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
Operation Triangulation is an ongoing APT campaign targeting iOS devices with zero-click iMessage exploits. The threat actor behind the campaign has been active since at least 2019 and continues to operate. The attack chain involves the delivery of a malicious iMessage attachment that launches a series of exploits, ultimately leading to the deployment of the TriangleDB implant. Kaspersky researchers have discovered and reported multiple vulnerabilities used in the campaign, with patches released by Apple.
Reports & references
- Kaspersky — 111669 (report)
- Kaspersky — 110916 (report)
- Kaspersky — 110847 (report)
- Kaspersky — 109842 (report)