{"id":56443,"date":"2023-06-05T14:32:57","date_gmt":"2023-06-05T06:32:57","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=56443"},"modified":"2023-06-05T14:32:59","modified_gmt":"2023-06-05T06:32:59","slug":"kaspersky-reports-on-new-mobile-apt-campaign-targeting-ios-devices","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2023\/06\/05\/kaspersky-reports-on-new-mobile-apt-campaign-targeting-ios-devices\/","title":{"rendered":"Kaspersky reports on new mobile APT campaign targeting iOS devices"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Kaspersky researchers have <a rel=\"noreferrer noopener\" href=\"https:\/\/securelist.com\/operation-triangulation\/109842\/\" target=\"_blank\">uncovered<\/a> an ongoing mobile Advanced Persistent Threat (APT) campaign targeting iOS devices with previously unknown malware. Dubbed as \u201cOperation Triangulation\u201d, the campaign distributes zero-click exploits via iMessage to run malware gaining complete control over the device and user data, with the final goal to spy on users.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky experts have <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/operation-triangulation\/109842\/\">uncovered<\/a> a new mobile APT campaign while monitoring the network traffic of its corporate Wi-Fi network using the Kaspersky Unified Monitoring and Analysis Platform (KUMA). Upon further analysis, company researchers discovered the threat actor has been targeting iOS devices of dozens of company employees.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The investigation of the attack technique is still ongoing, but so far Kaspersky researchers were able to identify the general infection sequence. The victim received a message via iMessage with an attachment containing a zero-click exploit. Without any further interaction, the message triggered a vulnerability that led to code execution for privilege escalation and provided full control over the infected device. Once the attacker successfully established its presence in the device, the message was automatically deleted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Further, the spyware quietly transmitted private information to remote servers: including microphone recordings, photos from instant messengers, geolocation and data about a number of other activities of the owner of the infected device.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During the analysis, it was confirmed that there was no impact on the company\u2019s products, technologies and services, and no Kaspersky customer user data or critical company processes were affected. The attackers could only access data stored on the infected devices. Although not certain, it is believed that the attack was not targeted specifically at Kaspersky \u2013 the company\u2019s just first to discover it. The following days will likely bring more clarity about the global exposure of this cyberattack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWhen it comes to cybersecurity, even the most secure operating systems can be compromised. As APT actors are constantly evolving their tactics and searching for new weaknesses to exploit, businesses must prioritize security of their systems. This involves prioritizing employee education and awareness, and providing them with the latest threat intelligence and tools to effectively recognize and defend against potential threats,\u201d commented Igor Kuznetsov, head of the EEMEA unit at Kaspersky Global Research and Analysis Team (GReAT).&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cOur investigation of the Triangulation operation continues. We expect further details on it to be shared soon, as there can be targets of this spy operation outside Kaspersky,\u201d added Kuznetsov.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Learn more about \u201cOperation Triangulation\u201d on <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/securelist.com\/trng-2023\/\">Securelist.com<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To check if your iOS device is infected or not, follow instructions on the website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In order to avoid falling victim to a targeted attack by a known or unknown threat actor, Kaspersky researchers recommend implementing the following measures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>For endpoint level detection, investigation, and timely remediation of incidents, use a reliable security solution for businesses, like Kaspersky Unified Monitoring and Analysis Platform (KUMA)<\/li>\n\n\n\n<li>Update Microsoft Windows OS and other third-party software as soon as possible and do so regularly<\/li>\n\n\n\n<li>Provide your SOC team with access to the latest threat intelligence (TI). <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/threat-intelligence\">Kaspersky Threat Intelligence<\/a> is a single point of access for the company\u2019s TI, providing it with cyberattack data and insights gathered by Kaspersky spanning over 20 years.<\/li>\n\n\n\n<li>Upskill your cybersecurity team to tackle the latest targeted threats with <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/xtraining.kaspersky.com\/?utm_source=pr-media&amp;utm_medium=partner&amp;utm_campaign=gl_xtr-gen-pr_je0066&amp;utm_content=sm-post&amp;utm_term=gl_pr-media_organic_66jpzgkgnjbgdrn&amp;redef=1&amp;THRU&amp;reseller=gl_xtr-gen-pr_acq_ona_smm__onl_b2b_pr-media_post_______\">Kaspersky online training<\/a> developed by GReAT experts<\/li>\n\n\n\n<li>As many targeted attacks start with phishing or other social engineering techniques, introduce security awareness training and teach practical skills to your team \u2013 for example, through the <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/small-to-medium-business-security\/security-awareness-platform\">Kaspersky Automated Security Awareness Platform<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky experts have uncovered a new mobile APT campaign while monitoring the network traffic of its corporate Wi-Fi network using the Kaspersky Unified Monitoring and Analysis Platform (KUMA). Upon further analysis, company researchers discovered the threat actor has been targeting iOS devices of dozens of company employees.\u00a0<\/p>\n","protected":false},"author":6,"featured_media":56448,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-56443","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/56443","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=56443"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/56443\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/56448"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=56443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=56443"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=56443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}