This Malware Targets iPhone Users via iMessage, Extracts Private Data

Prominent cybersecurity and anti-virus firm Kaspersky has discovered a new cyberattack threat that targets iPhone models running older versions of iOS via iMessage application. The malware, found when the company was monitoring its own Wi-Fi network for mobile devices, infects the phone via a received iMessage, which contains a malicious attachment. The threat doesn’t require the iPhone user to do anything and utilises iOS vulnerability to install a spyware that takes complete control of device and user data.

According to a report about their findings published by Kaspersky, the malicious attachment sent via iMessage executes a code without the need for any action from the user. The malicious code then runs a set of commands for collection of private user data.

Kaspersky CEO Eugene Kaspersky tweeted about the iOS cyberattack, detailing that the spyware extracts private information like microphone recordings, photos from instant messengers, geolocation, and other data and transmits it to remote servers. The firm has dubbed the cyberattack threat as “Operation Triangulation.”

Kaspersky said that the malware was found on the iPhones of dozens of employees and could target other iPhone users as well. He also added that the threat had been neutralised and details of the vulnerability have been sent to Apple. The CEO also noted that disabling the iMessage service would prevent vulnerable iOS devices from the attack.

The company said that after the malware is successfully installed on the device, the initial text and the accompanying exploit in the iMessage attachment are deleted. Kaspersky’s report said the attack was ongoing, and iOS 15.7 was the most recent version among the devices that were successfully targeted. iPhone models running iOS 16 appear to be safe from the threat, but Kaspersky did mention in the comments section of its report that they could not guarantee that other iOS versions were safe.

On Friday, Kaspersky also released tools for users to check if their device was infected.

Back in February, Apple released updates that fixed major vulnerabilities with iOS 16.3 and macOS 13.2 for supported iPhone, iPad and Mac models. At the time, Apple credited the researchers who found the flaws that allowed a remote user to bypass protections put in place by Apple and gain access to a user’s personal data as well as their camera, microphone, and call history.


Apple’s annual developer conference is just around the corner. From the company’s first mixed reality headset to new software updates, we discuss all the things we’re looking forward to seeing at WWDC 2023 on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated – see our ethics statement for details.

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TheDailyCheck is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected] The content will be deleted within 24 hours.