Researchers in collaboration with Kaspersky have uncovered information about a sophisticated iOS attack , which is considered one of the most advanced ever discovered.

The attack, known as “Operation Triangulation,” was first revealed last summer and its vulnerabilities were patched through iOS firmware updates. Kaspersky’s team has analyzed the malware and its corresponding exploits and, during a recent presentation, described the inner workings of this unprecedented attack. No specific source has been credited with the attack, although Kaspersky provided details to the Russian FSB, suggesting a link to services . “We are discovering and analyzing new attacks every day,” the researchers said.
Read more: Canada bans WeChat and Kaspersky apps on government devices
We have identified and reported more than thirty in-the-wild zero-days in products from Adobe, Apple, Google , and Microsoft. However, this is undoubtedly the most sophisticated attack chain we have ever seen.
What stood out to the Kaspersky team was the murky nature of the debugger abuses. Without proper documentation or guidance, an attacker would have to search persistently and determinedly to locate memory access registers.
“We don’t know how the attackers learned to use this hardware or what its purpose was,” explained researcher Boris Larin.

The priority for Kaspersky developers is to pay special attention to removing debugging and access before the code reaches production. Even if a feature is poorly documented and neglected, there is a chance that it could be exploited by an exploit.
See also: “Mysterious Elephant” group appears, Kaspersky reports
Source: thestack.technology
