Binary Validator is an iOS malware implant associated with the Operation Triangulation espionage campaign. It operates on compromised iPhones after initial access and is characterized by post-compromise collection, anti-forensics, and data exfiltration behavior. Observed capabilities include enumerating running processes, collecting device-identifying information such as the phone number and IMEI, and transmitting collected data to command-and-control infrastructure. Binary Validator also performs defense-evasion and cleanup actions by deleting crash logs that may reveal exploitation activity and by locating and removing traces of the malicious iMessage attachment used to gain access, including references stored in device databases. The malware’s behavior is consistent with a stealth-focused mobile spyware or backdoor component used in a targeted intrusion chain against iOS devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
AbstractEmu can collect device IP address and SIM information; Android/SpyAgent has collected device network information, such as the IMEI and the phone number; ANDROIDOS_ANSERVER.A gathers the device IMEI and IMSI; many listed mobile malware families collect IMEI, IMSI, ICCID, MEID, serial number, phone number, MAC address, IP address, carrier, MCC/MNC, and related device/network identifiers.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware/tool used in an intrusion chain that searched for and deleted the malicious iMessage attachment used for initial access.
Malware/tool involved in searching for and deleting the malicious iMessage attachment used for initial access.
Malware/tool involved in post-compromise cleanup by locating and deleting the malicious iMessage attachment used for initial access.
Malware observed exfiltrating collected data to its command-and-control server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.