Operation Triangulation

First seen
2019-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:13:45

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Operation Triangulation is an ongoing APT campaign targeting iOS devices with zero-click iMessage exploits. The threat actor behind the campaign has been active since at least 2019 and continues to operate. The attack chain involves the delivery of a malicious iMessage attachment that launches a series of exploits, ultimately leading to the deployment of the TriangleDB implant. Kaspersky researchers have discovered and reported multiple vulnerabilities used in the campaign, with patches released by Apple.

Reports & references

  • Kaspersky — 111669 (report)
  • Kaspersky — 110916 (report)
  • Kaspersky — 110847 (report)
  • Kaspersky — 109842 (report)

External references