Hacker News new | past | comments | ask | show | jobs | submit login
“Clickless” iOS exploits infect Kaspersky iPhones with never-before-seen malware (arstechnica.com)
116 points by samizdis on June 1, 2023 | hide | past | favorite | 41 comments



My first question upon seeing the title was "What are Kaspersky iPhones?"

Answered in the first paragraph: "Kaspersky has been hit by an advanced cyberattack that used clickless exploits to infect the iPhones of several dozen employees with malware ..."

So this was iPhones belonging to Kaspersky employees - though sounds like the exploit could hit any iPhone.


Would this be prevented if an iPhone were in Lockdown Mode? [1]

1: https://support.apple.com/en-us/HT212650


Given the exploit vector looks like yet another iMessage attachment bug,

> The target iOS device receives a message via the iMessage service, with an attachment containing an exploit.

and that one of the effects of Lockdown Mode is

> Messages - Most message attachment types are blocked, other than certain images, video, and audio. Some features, such as links and link previews, are unavailable.

It might be prevented. Pretty sure disabling iMessage altogether sidesteps this class of bugs too. I've lost track of how many times iMessage has been the root cause of "unattended iOS RCE," at this point it's almost user negligence to have left on.


I was surprised that the article didn't mention Lockdown Mode considering the likely overlap in features. It's even possible that Lockdown Mode was developed (at least in part) to defeat these types of exploits, given the timeline.


Apple has chosen that it is more important to exploit in-group bias with bubble colors than phone security.

I joke, but I can't tell you how annoying iMessage has been. Its so bad with non-iphones, we basically switch to email or teams when doing group communication.


Generally everyone uses WhatsApp already anyway.


Likely another C-based media codec or other similar legacy file reader bug.


Is there a way to disable only the iMessage attachments functionality? (as an alternative to going full lockdown)


I don't think this is possible, but I too wish it were. I hate the fact that you can't copy a link from Messages without it opening a preview. That means if you've been forwarded a link with trackers, it's impossible to remove the tracking bits before opening. Not good!


When you long-press a link, there's a button at the top right corner that says "Hide preview". If you press it, previews will stop opening automatically everywhere.


Wow, amazing. I always thought that was just to hide this preview. Thanks a million, anonymous HN commenter!


Lockdown Mode was added in iOS 16. The article only mentions iOS 15.7, saying there is no information whether iOS 16 is vulnerable (with or without Lockdown Mode), unfortunately.

It's curious they say iOS 16 was released "last month" when it was released last year.


> the fact of infection was detected by Kaspersky Unified Monitoring and Analysis Platform (KUMA), a native SIEM solution for information and event management; the system detected an anomaly in our network coming from Apple devices.

Interesting. This demonstrates the big downside of iOS's security model - it's basically impossible to run useful host-based IDS, which likely would have flagged this much more quickly.


Non-click exploits are freaky. I wish there was a way to detect if my device is compromised.


Treat all of your devices as compromised. Between the FBI breaking the terrorist's iphone, Pegasus, etc... It might be best to have a burner smart phone that you keep off 99.99% of the time and get your secrets off it only.


Or, you could just not have an iphone.


Lame comment, but for what its worth - I assume my iphone acts like a cia tacking device that sends all my info to nsa, so I never put anything on there that could get me in real trouble.

But it would suck if I got a text from a russian organized hacking criminal org that got a hold or my banking credentials.


Because Android is a far more secure platform and Google is a far more trustworthy custodian of your data?

Or are you recommending that one opt out of a good portion of society by not using a smartphone? For most people that is not really a convenient option.


Have there been any universal exploits like this on modern Android recently?

When people discuss android security issues its mostly about the guy who installed random app from gods know where and got into trouble


Android is just as vulnerable to 0-click exploits as iOS is. In some ways it is more exposed.


How is android more exposed?

Project Zero people have worked very hard to harden the core system. That doesn't completely eliminate 0days but makes finding them much harder.


Hopefully the diversity in the Android ecosystem (seems like every Android phone vendor wants to run their own variants of various bits) makes it harder to exploit all Android devices with one exploit.

Also has the downside of increasing the attack surface, but yeah. I feel like it's potatoes grown from "seed" potatoes vs. potatoes grown from actual seeds.


Blame apple for this.

I've always said you should be able to see what's on your own device, but apple doesn't allow it, you can't access the entire filesystem.

Also you can't see what processes are running, what they are doing, or look at the network traffic being generated.


It's not particularly convenient but iOS does provide ways to fetch a list of running processes for debugging purposes.


iOS makes this very difficult, even for security researchers. Everyone, irregardless of skill level should be able to have some basic control over the device they use


I curiously look forward to a self-propagating worm that bricks all iphones with a zero click bug.

It will be a fascinating day in human history.


Interesting that people in sensitive positions would use foreign made smartphones. Surely they are Russian companies that manufacture at least low end Android phones?


Android would still be running Google so I guess it's a risk either way. At least Apple seem to be more secure by default without any user config.

Looked this up and there is indeed a Russian company called Ayya, making smartphones with a switch to disable the microphone. It'll also be changing from Android to a domestically made OS, it seems. https://www.indiatimes.com/technology/news/russia-ayya-t1-sm...


Doesn't need to be a Google version of Android. Since it's open source, there's plenty of non-Google forks, such as this one, focusing on privacy and security: https://grapheneos.org/


This was delivered by a remote exploit, not a supply chain issue. How would buying a domestically produced phone prevent this?


There's an entire section in the article titled: "Russia accuses Apple of colluding with the NSA". I would assume if the FSB isn't just blowing smoke, then your question is answered.


I assume the norm, or at least what they want to be the norm, is Huawei, Oppo, or Xiaomi. Regardless of what manufacturer or OS you use, it will not protect you from motivated nation states or companies like NSO.

If you are truly concerned for your life, especially in authoritarian regimes, don't carry a phone.


What an absolute joke that you can upload files on demand to someones phone as long as you have a number or an email


What is email if not a way to send files to other people's computers? I don't understand your point.


Same case with email too. I prefer to access email through a browser where you have a little more control over what gets loaded. Atleast then it's above a clickless.


Gmail is not my computer.


The moment you load a message preview, it may as well be.


The message preview is a few kilobytes of text, which is very different from loading an arbitrary (and arbitrarily large) file onto my machine.



This is why on our GrapheneOS devices we use a messenger that is written in Rust.


Looks like kaspersky just tries to blame iphones.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: