[HN Gopher] Possible US Government iPhone-Hacking Toolkit in for...
___________________________________________________________________
Possible US Government iPhone-Hacking Toolkit in foreign spy and
criminal hands
Author : alwillis
Score : 132 points
Date : 2026-03-03 19:34 UTC (3 hours ago)
(HTM) web link (www.wired.com)
(TXT) w3m dump (www.wired.com)
| oxfeed65261 wrote:
| https://archive.ph/r7jGc
| mentalgear wrote:
| How could something as sensitive get out of an administration as
| competent as the current one? At least they have no access to
| lets say AI or autonomous weapons and the tools of mass
| surveillance ...
| grosswait wrote:
| The constant injection of political view points on hn is
| becoming exhausting
| happyopossum wrote:
| "Possible" stripped from the headline on HN. That word seems
| particularly important given that it's speculative:
|
| "Clues suggest it was originally built for the US government."
| tptacek wrote:
| The Google threat analysis report doesn't say anything about
| USG involvement; that it was found on compromised Ukrainian
| sites, has code written in "native English", but also signs of
| LLM authorship. The Google report says the kit they found can't
| compromise current iOS, which is a capability you'd assume USG
| would have --- though it's important remember that "USG"
| comprises dozens of different buyers each with different
| toolchains.
|
| Maybe this was the Fisheries Department exploit toolkit.
|
| iVerify, which spun out of Trail of Bits and presumably knows
| what they're talking about, says it bears "hallmarks" of being
| connected to USG CNE work. I believe it. But the USG is on net
| a buyer, not a producer, of CNE tooling. Whatever a given
| service agency or IC arm buys, dozens of other aligned
| countries are also buying.
|
| (And, of course, the non-aligned countries have their own
| commercial supply chains).
| bri3d wrote:
| I don't think the ancient nature of the exploit chain has
| much bearing on the origin. I think it points away from the
| actual 2025 campaigns being USG-attached, but I don't think
| anyone was suggesting that to start with - the Google report
| makes it pretty clear that they believe the same code was
| resold to several parties, either in parallel or
| sequentially, around this time frame.
|
| I think the notion here is that either:
|
| * There's a shared upstream origin or author between this
| toolkit and the Operation Triangulation toolkit ahead of the
| use in Operation Triangulation (ie - someone sold this chain
| to both the Operation Triangulation authors and a third
| party). I actually think that the uses of specifically
| structured code-names internally and the overall structure of
| the codebase described in the Google writeup make this theory
| less likely; building an exploit toolkit while using these
| practices to cosplay as a US-government affiliated engineer
| would be clever and fun, but it's not something we've really
| seen before.
|
| * This toolkit originated from (whether it was leaked,
| compromised, or resold) the same actor who was responsible
| for Operation Triangulation.
| tptacek wrote:
| Right, I agree with you; my thing is mostly just
| differentiating between CNE enablement packages the USG
| itself creates vs CNE enablement packages that are on offer
| to every USG-aligned country, of which there are a bunch.
| Simulacra wrote:
| Good point, that was also struck by the comment that it's
| infected "tens of thousands" phones. That's a minuscule
| rounding error.
| dang wrote:
| The title limit is 80 chars, if anyone wants to figure out a
| decent way to squeeze possibility back in there.
| alwa wrote:
| "Possible US-Gov-made iPhone-hacking toolkit is now in
| foreign and criminal hands" ?
| dang wrote:
| We try to avoid abbreviations if possible. You spurred me
| to take another crack at it and I think it worked this
| time? Happy to edit again if not...
| irishcoffee wrote:
| A US Govt iPhone-hacking suite is now possibly in criminal
| hands
|
| 15 chars to spare!
| dang wrote:
| I think the "possibly" is supposed to mean "possibly
| produced by the US government"
| irishcoffee wrote:
| Good point.
| doctorpangloss wrote:
| the government doesn't have superpowerful code crackers though
|
| it has a guy working at apple who introduces the subtle
| vulnerability he is instructed to do
| tptacek wrote:
| I expect the evidence for this claim is axiomatic, which is to
| say that you think it sounds good.
| lightedman wrote:
| No, anyone who remembers the Best Buy/FBI debacle knows that
| this statement is very well-grounded in reality. If you took
| your laptop to Best Buy for repairs, the FBI got a copy of
| your hard drive contents.
| majorchord wrote:
| Source:
| doctorpangloss wrote:
| haha yeah, thanks for the compliment
| joshrw wrote:
| Hello, have you heard of the Snowden revelations? What OP was
| referring to are called bugdoors.
| thesuitonym wrote:
| Those two are not mutually exclusive.
| 8cvor6j844qw_d6 wrote:
| Yeah. TAO was intercepting Cisco routers in transit and
| installing implants.
|
| The leap from supply chain interdiction to cooperative insiders
| isn't a big one.
| everdrive wrote:
| No matter the risk, I must carry my smartphone everywhere and
| install every app. It would be unimaginable to have the urge to
| look something up, but then wait to do it later until I'm using a
| real computer. No negative outcome will EVER shake my deep,
| permanent need to carry a smartphone all the time and use it for
| as much as possible.
| theearling wrote:
| Webapps exist for a reason, they don't get all the special
| permissions apps get when fully installed.
|
| at the very least use a VPN / more secure phone like a pixel
| with graphene
|
| You keep doing you though
| thewebguyd wrote:
| Ironically, the exploits in this leaked kit all involved
| flaws in webkit, so you'd have been safer sticking to native
| apps assuming they didn't have any webviews in them to load
| the malicious site.
| SpaceManNabs wrote:
| WebView is the worst experience I have on any smart phone
| or mobile app.
|
| The fact that there is no option so that any webview by
| default opens in safari across all app in ios is horrible.
|
| i am not surprised it is riddled with security holes.
| thesuitonym wrote:
| A VPN won't help you if your device is compromised. A VPN
| won't help you if the server is compromised. A VPN won't help
| you if the VPN is compromised.
|
| I really wish people would understand that VPNs are not
| magical, unbreakable security. VPNs are barely security at
| all, and commercial VPNs even less so.
| theearling wrote:
| oh 100% agree here, I was just confused at the OP comments
| evangelism of installing and keeping his phone on his for
| those quick fix google searches
| stock_toaster wrote:
| With this administration? Color me unsurprised.
___________________________________________________________________
(page generated 2026-03-03 23:00 UTC)