Connect with us

Hi, what are you looking for?

HEADLINES

Kaspersky releases utility for malware detection

Following the report on the Operation Triangulation campaign targeting iOS devices, Kaspersky researchers have released a special “triangle_check” utility that automatically searches for the malware infection. The tool is publicly shared on GitHub and available for macOS, Windows and Linux.

Following the report on the Operation Triangulation campaign targeting iOS devices, Kaspersky researchers have released a special “triangle_check” utility that automatically searches for the malware infection. The tool is publicly shared on GitHub and available for macOS, Windows and Linux.

On June 1, 2023, Kaspersky reported about a new mobile APT that has been targeting iOS devices. The campaign employs zero-click exploits delivered via iMessage to install malware and gain complete control over the device and user data, with the ultimate goal of hiddenly spying on users. Among the victims were Kaspersky’s own employees; however, the company’s researchers believe the scope of the attack extends far beyond the organization. Continuing the investigation, Kaspersky researchers aim to bring more clarity and further details on the worldwide proliferation of this spyware.

The initial report already included a detailed description for self-checking compromise trail mechanisms using the MVT tool. Recently, Kaspersky publicly released on GitHub a special utility called “triangle_check”. This utility, available for macOS, Windows and Linux in Python, allows users to automatically search for traces of malware infection and therefore check whether a device has been infected or not.

Before installing the utility, the user should first do a backup of the device. Once a back up copy is created, a user can install and run the tool. If indicators of compromise are detected, the tool will show a “DETECTED” notification that confirms the device has been infected. The “SUSPICION” message indicates detection of less unambiguous indicators – pointing to a likely infection. A “No traces of compromise were identified” message will be shown if no IoCs were detected at all.

Advertisement. Scroll to continue reading.

“Today we are proud to release a free public tool that allows users to check whether they were hit by the newly emerged sophisticated threat. With cross-platform capabilities, the “triangle_check” allows users to scan their devices automatically,” commented Igor Kuznetsov, head of the EEMEA unit at Kaspersky Global Research and Analysis Team (GReAT).

 “We urge the cybersecurity community to unite forces in the research of the new APT to build a safer digital world,” added Kuznetsov.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Acting on reports about a suspicious message urging customers to click a malicious link to redeem ‘Smart points’, the telco quickly sprang into action...

HEADLINES

Likening the Converge network to a digital fortress, CISO Andrew T.  Malijan said that its battlements were strengthened in 2024 as it blocked a...

HEADLINES

ThinkShield Firmware Assurance is one of the only computer OEM solutions to enable deep visibility and protection below the operating system (OS) by embracing Zero...

HEADLINES

Kaspersky experts have uncovered a series of scams related to the growing demand, ranging from impersonating trusted brands to creating entirely fraudulent storefronts.

HEADLINES

This achievement highlights the increasing demand for Sophos’ proactive, expert-led security solutions, which help organizations of all sizes stay protected 24/7 against increasingly sophisticated...

HEADLINES

Trend's 2025 predictions report warns of the potential for malicious "digital twins," where breached/leaked personal information (PII) is used to train an LLM to...

HEADLINES

The findings show that platform security – securing the hardware and firmware of PCs, laptops and printers – is often overlooked, weakening cybersecurity posture...

HEADLINES

In rigorous evaluations conducted by prestigious cybersecurity testing organizations, Kaspersky Plus (starting in Q4 2024, Kaspersky Premium), Kaspersky Endpoint Security for Business (KESB), and...

Advertisement