Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionageendpoint-software-vulnerabilityinitial-access-methodremote-access-implant

Operation Triangulation Used Four Zero-Days to Spy on iPhones

Updated 1mo agoFirst seen May 25, 20267 sources

Researchers disclosed Operation Triangulation, an iPhone espionage campaign that infected devices through iMessage and deployed a sophisticated spyware implant on iOS. Reporting tied the operation to a chain of four zero-day vulnerabilities, including flaws in Apple’s processing of messages and a hardware-based feature that enabled attackers to bypass protections that were largely undocumented outside Apple. Kaspersky said the malware targeted iPhones used by its employees, while later technical analysis and conference presentations detailed how the implant gained code execution, escalated privileges, and maintained stealth on compromised devices.

The campaign quickly drew geopolitical attention after Russian authorities accused Apple of cooperating with the NSA in the spying operation, an allegation that was widely reported but not substantiated by public technical evidence. Subsequent coverage focused on the exploit kit sometimes referred to as Coruna, with Kaspersky later saying it had found no signs that the toolkit was created by the United States. The case remains notable for showing that attackers combined multiple iOS zero-days with obscure Apple hardware behavior to build a highly advanced surveillance platform against iPhone users.

Share:
Operation Triangulation Used Four Zero-Days to Spy on iPhones
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 4, 20264mo ago

Kaspersky rejects claims that the Coruna iPhone exploit kit was made by the US

In March 2026, Kaspersky said it had found no signs that the Coruna exploit framework associated with Operation Triangulation had been developed by the United States. The statement represented a later attribution-related update to the long-running investigation.

Dec 30, 20232y ago

Analysis reveals Triangulation used four zero-days and a hardware feature

Late-2023 and early-2024 reporting said the iPhone spyware campaign relied on four zero-day vulnerabilities and abused an Apple hardware-based feature that had been largely undocumented. These findings significantly deepened understanding of the sophistication of the exploit chain.

Dec 27, 20232y ago

Researchers present deeper technical findings on Operation Triangulation

At the end of 2023, researchers publicly shared additional analysis of Operation Triangulation, including more detail on the exploit chain and how attackers compromised researchers' iPhones. This marked a broader technical disclosure beyond the initial June reporting.

Jun 21, 20233y ago

Researchers publish a report detailing Operation Triangulation's spyware implant

A June 2023 report exposed technical details of the Operation Triangulation implant targeting iOS devices, describing the infection chain and spyware capabilities. The disclosure expanded public understanding of how the campaign operated on compromised iPhones.

Jun 1, 20233y ago

Russia accuses Apple and the NSA over the iPhone spying campaign

Russian authorities publicly alleged that Apple had cooperated with the NSA in a spying operation involving infected iPhones, while Kaspersky said it had found evidence of targeted compromises but did not attribute the campaign to Apple. The accusation brought Operation Triangulation into wider public view.

Kaspersky detects iPhone compromise inside its corporate network

Kaspersky reported discovering that several employees' iPhones had been infected by a previously unknown iOS spyware campaign later named Operation Triangulation. The company said the attack used invisible iMessage-delivered exploits and affected devices running recent iOS versions.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Operation Triangulation Used Four Zero-Days to Spy on iPhones | Mallory