Kaspersky Releases Utility to Detect Operation Triangulation iPhone Compromise
Kaspersky published a utility to help organizations and individuals identify traces of Operation Triangulation, an iPhone-focused espionage campaign uncovered on corporate devices. The tool is designed to detect indicators left by the attack chain, which used previously unknown iOS exploits to compromise devices through iMessage without user interaction and then deploy malware for covert data collection.
The release gives defenders a practical way to check Apple mobile devices for evidence of compromise tied to the campaign and supports incident response efforts where targeted surveillance is suspected. Operation Triangulation drew attention because it relied on a sophisticated zero-click infection path and targeted mobile endpoints that are often harder for enterprises to inspect, making forensic detection tools especially important for security teams.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
1 event from the most recent confirmed update back to the earliest known activity.
Kaspersky publishes utility to detect Operation Triangulation traces
Securelist published a tool intended to help users find traces of the Operation Triangulation campaign on affected devices. The reference provides no earlier incident details, so this publication is the only distinct event supported by the content.
Sources
3 references tracked. Mallory keeps watching after this page renders.
GitHub - KasperskyLab/triangle_check · GitHub
github.com
Open sourceTool to find the Operation Triangulation traces | Securelist
securelist.com
Open sourceNew tool scans iPhones for 'Triangulation' malware infection
bleepingcomputer.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


