TriangleDB is a sophisticated in-memory iOS spyware implant associated with Operation Triangulation, a long-running espionage campaign active since at least 2019. It is deployed after a zero-click iMessage exploitation chain achieves code execution and then gains root privileges through kernel exploitation on targeted iPhones. The implant is loaded directly into memory, lacks conventional persistence across reboot, and can self-remove after a defined period unless operators extend its lifetime, requiring reinfection after device restart.
TriangleDB functions as a modular surveillance platform. Its core capabilities include collecting device identifiers and system information, enumerating running processes, manipulating files, deleting attacker-specified files or implant components, exfiltrating files, retrieving credentials and other secrets from the iOS keychain, and monitoring geolocation. It communicates periodically with command-and-control infrastructure over HTTPS using serialized messages and encrypted exchanges, receives tasking from operators, and can reflectively load additional in-memory modules to expand functionality. Reported auxiliary modules support activities such as querying on-device databases, prolonged microphone recording, and theft of chat data from applications including WhatsApp and Telegram.
The malware has been described as highly stealthy. It deletes traces related to earlier infection stages, operates only in memory, and is designed for covert intelligence collection rather than disruptive effects. Known targeting is tied to high-value espionage objectives, including journalists, senior officials, governmental, diplomatic, and commercial entities. TriangleDB is one of the principal implants publicly linked to Operation Triangulation and stands alongside other premium mobile spyware platforms such as Pegasus and Predator in discussions of advanced iOS surveillance tooling.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On June 21, 2023, Apple releases updates for iOS 15.x and 16.x, addressing two vulnerabilities used in the attack: CVE-2023-32434 in the iOS kernel and CVE-2023-32435 in the WebKit browser engine.
July 24, 2023: Apple releases updates for iOS 15.x and 16.x, addressing ... CVE-2023-41990 in the FontParser font processing mechanism. These vulnerabilities were also part of the infection chain for Operation Triangulation.
After passing a check, the script on the web page additionally exploits the CVE-2023-32435 vulnerability and loads binary code into the device's memory, gaining root privileges...
July 24, 2023: Apple releases updates for iOS 15.x and 16.x, addressing the CVE-2023-38606 vulnerability in the iOS kernel... These vulnerabilities were also part of the infection chain for Operation Triangulation.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
It is deployed in memory, meaning that all traces of the implant are lost when the device gets rebooted.
"This binary validator also deletes traces of the received iMessage..."
"The web page contains a validator script that analyzes the parameters of the infected smartphone and decides whether to continue the infection."; "...multi-stage validation of potential victims... infect only their intended targets and evade security researchers."
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
CRXQueryShowTables Obtains a listing of a specified directory with the fts API.
"The web page contains a validator script that analyzes the parameters of the infected smartphone and decides whether to continue the infection."; "...multi-stage validation of potential victims... infect only their intended targets and evade security researchers."
AbstractEmu can collect files from or inspect the device’s filesystem. AhRat can find and exfiltrate files with certain extensions, such as .jpg, .mp4, .html, .docx, and .pdf. BOULDSPY can access browser history and bookmarks, and can list all files and folders on the device.
One of the interesting commands we discovered is called CRXPollRecords. It monitors changes in folders, looking for modified files that have names matching specified regular expressions... Such files are then scheduled for uploading to the C2 server.
The configuration of the implant contains two servers: the primary and the fallback (contained in the lS and lSf configuration fields). Normally, the implant uses the primary server, and, in case of an error, it switches to the fallback server
SpyNote RAT can copy files from the device to the C2 server. ViceLeaker can copy arbitrary files from the device to the C2 server, can exfiltrate browsing history, can exfiltrate the SD card structure, and can exfiltrate pictures as the user takes them. TriangleDB has collected and exfiltrated files.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile spyware referenced as part of ongoing campaigns against journalists and senior officials.
Memory-resident, modular iOS spyware implant used in Operation Triangulation. Capabilities include uploading files, extracting keychain data, tracking geolocation, modifying files/processes, prolonged microphone recording (including in airplane mode), querying on-device databases, and stealing chats from WhatsApp and Telegram. It deletes traces of the initial iMessage and is removed on reboot, enabling reinfection via repeated iMessage delivery.
In-memory iOS spyware/implant used in Operation Triangulation; communicates with C2 for tasking, can browse/modify device files, steal keychain credentials, retrieve geolocation, and execute additional modules.
An in-memory iOS spyware/implant used in Operation Triangulation. It achieves root privileges via a kernel vulnerability, communicates with C2 over HTTPS using Protobuf with 3DES/RSA encryption, beacons system/device info, and supports commands for filesystem/process interaction, keychain dumping, geolocation monitoring, and reflective in-memory loading/execution of additional Mach-O modules. It lacks persistence across reboot and self-uninstalls after ~30 days unless extended by the operator.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.