Light

Episode #929 Quiz

Operation Triangle
Date: 2023-06-27 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

Kaspersky’s Operation Triangulation showed a four-year, zero-click iMessage spyware chain: a malicious attachment triggered code execution, downloaded privilege-escalation exploits, then a root implant named TriangleDB. It communicated over HTTPS with Protobuf, 3DES, and RSA, sent heartbeats, exfiltrated keychain, files, and geolocation, persisted only in memory, and self-uninstalled after 30 days.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what specific browser-rendering approach did DuckDuckGo say its new Windows browser uses for web page rendering?
Question 2: What did Kaspersky identify as the initial, userless trigger for the iPhone spyware chain in Operation Triangulation?
Question 3: Which statement best matches the persistence behavior Kaspersky described for the TriangleDB implant?
Question 4: What did Kaspersky say was the mechanism behind the name 'Triangulation'?
Question 5: Which set of communications artifacts did Kaspersky say can help identify an active Operation Triangulation infection?
Cancel