---
title: "New Zero-Click Hack with Stealthy Root Privilege Malware Targets iOS Users | DuoCircle"
description: "If you think iOS devices are tamper-proof, you might be mistaken because Operation Triangulation has proved otherwise."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/data-privacy/new-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users/"
---

Quick Answer

Operation Triangulation is an iOS APT campaign that uses a zero-click iMessage exploit to deliver malware that runs with root privileges. The malicious attachment triggers automatically with no user interaction, then pulls additional payloads to escalate privileges and install final-stage malware. Once active, the implant can capture microphone audio, geolocation, photos from messengers, and other data, and exfiltrate it to a remote server. The initial message and exploit traces are auto-deleted to evade detection. Because iOS limits persistence, devices can be reinfected after reboot. Kaspersky discovered the campaign through offline backups and observed it on devices running iOS 15.7\. Russia's FSB issued a parallel advisory alleging US intelligence involvement; Apple has denied any backdoor cooperation. Scope and whether a zero-day is in play remain unconfirmed.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fdata-privacy%2Fnew-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=New%20Zero-Click%20Hack%20with%20Stealthy%20Root%20Privilege%20Malware%20Targets%20iOS%20Users&url=undefined%2Fblog%2Fdata-privacy%2Fnew-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fdata-privacy%2Fnew-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fdata-privacy%2Fnew-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users%2F&title=New%20Zero-Click%20Hack%20with%20Stealthy%20Root%20Privilege%20Malware%20Targets%20iOS%20Users "Share on Reddit") [ ](mailto:?subject=New%20Zero-Click%20Hack%20with%20Stealthy%20Root%20Privilege%20Malware%20Targets%20iOS%20Users&body=Check out this article: undefined%2Fblog%2Fdata-privacy%2Fnew-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users%2F "Share via Email") 

![Malware](https://media.mailhop.org/duocircle/images/2023/06/email-smtp-service-7580.jpg) 

_If you think iOS devices are tamper-proof, you might be mistaken because **Operation Triangulation** has proved otherwise. The novel ‘zero-click’ compromise uses stealthy root privilege malware to hack into iOS systems indicating the need for enhanced [cybersecurity](/) measures for iPhones as well._

iOS users beware, Operation Triangulation, a **previously unknown** APT targeting iOS devices, is here. Since the targets get infected using [zero-click exploits](https://www.privacyaffairs.com/zero-click-explois/#:~:text=Summary%3A%20In%20this%20guide%20I,or%20spy%20on%20the%20victim.) through the iMessage Platform, users do not have any control over their devices.

[Kaspersky](https://securelist.com/operation-triangulation/109842/) says the malware gains absolute control of the device and user data because it runs with **root privileges**. Kaspersky adds that it discovered the traces of compromised iOS devices from their offline backups.

## How Did the Attack Originate?

The iOS device receives a message containing an **attachment** bearing the malicious code. Since the exploit falls under the zero-click category, the vulnerability gets triggered without any interaction from the user side. The code execution happens automatically once the message arrives on the device.

The malicious exploit has **highly advanced** configurations, enabling it to retrieve additional payloads for privilege escalation. Kaspersky has said it can drop a final stage malware from a [remote server](https://cybernews.com/news/shein-android-app-sent-data-remote-servers/) that acts as a fully featured APT platform.

[![Malware ](https://media.mailhop.org/duocircle/images/2023/06/hosted-email-server-7580.jpg)](https://media.mailhop.org/duocircle/images/2023/06/hosted-email-server-7580.jpg)

Since the implant runs with root privileges, it can **harvest sensitive information** and run code downloaded as plugin modules from the server. In addition, the [malware](/resources/malware-and-its-defense-mechanism) can transmit private information to remote servers. _It includes microphone recordings, geolocation information, **critical data** about other activities on the device, and even photos from instant messengers_.

The most critical aspect of this [spyware](https://www.securityweek.com/spyware-found-in-google-play-apps-with-over-420-million-downloads/) is that it **auto-deletes the initial message** and traces of the exploit in its final phase to avoid detection. Kaspersky added that since the malicious toolset does not support persistence because of iOS’s limitations, multiple affected devices could have gotten **reinfected** after rebooting, as indicated by their timelines.

## The Scope of the Attack

Kaspersky has mentioned that it needs to be clarified about the precise **scale and scope** of the campaign. However, it maintains that the attacks are ongoing, especially with penetrations observed in devices running iOS 15.7, a recently released iOS version.

It also **requires clarification** on whether the attack vector is exploiting a ‘[zero-day vulnerability](/email-security/unpatched-dogwalk-a-new-microsoft-zero-day-vulnerability/),’ i.e., a flaw attackers detect in the system before the original developer, which, in this case, is Apple, becomes aware of it. iOS released its latest update, 16.5, recently. Apple had also released another update, 15.7.6, last month.

[![malware](https://media.mailhop.org/duocircle/images/2023/06/windows-smtp-service-7581.jpg)](https://media.mailhop.org/duocircle/images/2023/06/windows-smtp-service-7581.jpg)

## International Impact

Kremlin has accused the US intelligence agencies of purposely compromising **thousands of Apple devices** belonging to domestic Russian subscribers and international diplomats using **unknown pathways** as a part of a reconnaissance operation. Russia’s FSB (Federal Security Service) has issued an [advisory](https://www.fsb.ru/fsb/press/message/single.htm!id=10439739@fsbMessage.html) coinciding with Kaspersky’s findings.

FSB also alleges close cooperation between the NSA (National Security Agency) and Apple with an intent to target **Russian iOS devices**. However, Apple has categorically [stated](https://www.reuters.com/technology/russias-fsb-says-us-nsa-penetrated-thousands-apple-phones-spy-plot-2023-06-01/) that it has never worked clandestinely or will ever do so with any governmental organization to insert a **backdoor** into its products.

But the Russian Ministry of Foreign Affairs does not think so because they feel that [US intelligence agencies](https://www.aljazeera.com/news/2021/1/5/us-intelligence-agencies-say-russia-likely-behind-govt-hack) have **used IT corporate giants** for decades to spy on the personal information of internal users of other countries without their knowledge. However, the allegation this time is that they have exploited the [vulnerabilities](/email-security/microsoft-server-exchange-vulnerabilities-are-among-the-most-exploited-reports-cisa/) in **US-made** iPhones and other devices running on iOS. This controversy highlights the importance of being able to [detect spyware on iPhone](https://clario.co/blog/how-to-detect-spyware-on-iphone/) to ensure your personal data remains protected.

_Kaspersky corroborates that the two activities could be related because they **overlap** in the IoCs (indicators of compromise) released by RU-CERT._

## Final Words

Kaspersky concludes that Operation Triangulation is a highly complex, professionally targeted [cyberattack](https://cosmeticsbusiness.com/news/article%5Fpage/Boots%5Fhit%5Fby%5FRussia-linked%5Fcyber%5Fattack%5Fwith%5Femployee%5Fdetails%5Fstolen/209303) because the targets include several iPhones belonging to **senior-level officials**. Nevertheless, the actual extent of exposure of this supposed espionage campaign has yet to be ascertained.

## Topics

NewsSecurityUpdates 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdata-privacy%2Fnew-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users%2F) [ ](https://twitter.com/intent/tweet?text=New%20Zero-Click%20Hack%20with%20Stealthy%20Root%20Privilege%20Malware%20Targets%20iOS%20Users&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdata-privacy%2Fnew-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fdata-privacy%2Fnew-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users%2F) Copy 

Related Articles

- [ ![Email Threats](https://media.mailhop.org/duocircle/images/2023/07/hosted-email-server-3175.jpg)  Are MortalKombat Ransomware and Tengyun Snake Attacks Emerging Email Threats? Blog ](/blog/data-privacy/are-mortalkombat-ransomware-and-tengyun-snake-attacks-emerging-email-threats/)
- [ ![Hacker Taunts](https://media.mailhop.org/duocircle/images/2022/09/spf-record-tester-7545.jpg)  Hacker Taunts TikTok After Stealing Over 2 Billion Records in a Massive Data Breach Blog ](/blog/data-privacy/hacker-taunts-tiktok-after-stealing-over-2-billion-records-in-a-massive-data-breach/)
- [ ![IntelBroker Threat Actors](https://media.mailhop.org/duocircle/images/2023/02/spf-record-generator-7980.jpg)  IntelBroker Threat Actors Steal Sensitive Data of 11 Million Weee Customers Blog ](/blog/data-privacy/intelbroker-threat-actors-steal-sensitive-data-of-11-million-weee-customers/)
- [ ![DuoCircle blog post image](https://media.mailhop.org/duocircle/images/2023/05/SPF-record-checker-7009.jpg)  Malicious Actors Use Azure Serial Console to Gain Unauthorized Access to Microsoft VMs Blog ](/blog/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/)

## Related Articles

[  Privacy 5m  Are MortalKombat Ransomware and Tengyun Snake Attacks Emerging Email Threats?  Jul 20, 2023 ](/blog/data-privacy/are-mortalkombat-ransomware-and-tengyun-snake-attacks-emerging-email-threats/)[  Privacy 6m  Hacker Taunts TikTok After Stealing Over 2 Billion Records in a Massive Data Breach  Sep 19, 2022 ](/blog/data-privacy/hacker-taunts-tiktok-after-stealing-over-2-billion-records-in-a-massive-data-breach/)[  Privacy 7m  IntelBroker Threat Actors Steal Sensitive Data of 11 Million Weee Customers  Feb 20, 2023 ](/blog/data-privacy/intelbroker-threat-actors-steal-sensitive-data-of-11-million-weee-customers/)[  Privacy 4m  Malicious Actors Use Azure Serial Console to Gain Unauthorized Access to Microsoft VMs  May 25, 2023 ](/blog/data-privacy/malicious-actors-use-azure-serial-console-to-gain-unauthorized-access-to-microsoft-vms/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"New Zero-Click Hack with Stealthy Root Privilege Malware Targets iOS Users","description":"If you think iOS devices are tamper-proof, you might be mistaken because Operation Triangulation has proved otherwise.","url":"https://www.duocircle.com/blog/data-privacy/new-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users/","datePublished":"2023-06-07T16:20:09.000Z","dateModified":"2025-05-29T12:48:56.000Z","dateCreated":"2023-06-07T16:20:09.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/data-privacy/new-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users/"},"articleSection":"data-privacy","keywords":"News, Security, Updates","wordCount":643,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/06/email-smtp-service-7580.jpg","caption":"Malware","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Privacy"},{"@type":"ListItem","position":3,"name":"New Zero-Click Hack with Stealthy Root Privilege Malware Targets iOS Users","item":"https://www.duocircle.com/blog/data-privacy/new-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Privacy","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"New Zero-Click Hack with Stealthy Root Privilege Malware Targets iOS Users","item":"https://www.duocircle.com/blog/data-privacy/new-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"New Zero-Click Hack with Stealthy Root Privilege Malware Targets iOS Users","description":"If you think iOS devices are tamper-proof, you might be mistaken because Operation Triangulation has proved otherwise.","url":"https://www.duocircle.com/blog/data-privacy/new-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users/","datePublished":"2023-06-07T16:20:09.000Z","dateModified":"2025-05-29T12:48:56.000Z","dateCreated":"2023-06-07T16:20:09.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/data-privacy/new-zero-click-hack-with-stealthy-root-privilege-malware-targets-ios-users/"},"articleSection":"data-privacy","keywords":"News, Security, Updates","wordCount":643,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2023/06/email-smtp-service-7580.jpg","caption":"Malware","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
