[HN Gopher] Possible US Government iPhone-Hacking Toolkit in for...
       ___________________________________________________________________
        
       Possible US Government iPhone-Hacking Toolkit in foreign spy and
       criminal hands
        
       Author : alwillis
       Score  : 132 points
       Date   : 2026-03-03 19:34 UTC (3 hours ago)
        
 (HTM) web link (www.wired.com)
 (TXT) w3m dump (www.wired.com)
        
       | oxfeed65261 wrote:
       | https://archive.ph/r7jGc
        
       | mentalgear wrote:
       | How could something as sensitive get out of an administration as
       | competent as the current one? At least they have no access to
       | lets say AI or autonomous weapons and the tools of mass
       | surveillance ...
        
         | grosswait wrote:
         | The constant injection of political view points on hn is
         | becoming exhausting
        
       | happyopossum wrote:
       | "Possible" stripped from the headline on HN. That word seems
       | particularly important given that it's speculative:
       | 
       | "Clues suggest it was originally built for the US government."
        
         | tptacek wrote:
         | The Google threat analysis report doesn't say anything about
         | USG involvement; that it was found on compromised Ukrainian
         | sites, has code written in "native English", but also signs of
         | LLM authorship. The Google report says the kit they found can't
         | compromise current iOS, which is a capability you'd assume USG
         | would have --- though it's important remember that "USG"
         | comprises dozens of different buyers each with different
         | toolchains.
         | 
         | Maybe this was the Fisheries Department exploit toolkit.
         | 
         | iVerify, which spun out of Trail of Bits and presumably knows
         | what they're talking about, says it bears "hallmarks" of being
         | connected to USG CNE work. I believe it. But the USG is on net
         | a buyer, not a producer, of CNE tooling. Whatever a given
         | service agency or IC arm buys, dozens of other aligned
         | countries are also buying.
         | 
         | (And, of course, the non-aligned countries have their own
         | commercial supply chains).
        
           | bri3d wrote:
           | I don't think the ancient nature of the exploit chain has
           | much bearing on the origin. I think it points away from the
           | actual 2025 campaigns being USG-attached, but I don't think
           | anyone was suggesting that to start with - the Google report
           | makes it pretty clear that they believe the same code was
           | resold to several parties, either in parallel or
           | sequentially, around this time frame.
           | 
           | I think the notion here is that either:
           | 
           | * There's a shared upstream origin or author between this
           | toolkit and the Operation Triangulation toolkit ahead of the
           | use in Operation Triangulation (ie - someone sold this chain
           | to both the Operation Triangulation authors and a third
           | party). I actually think that the uses of specifically
           | structured code-names internally and the overall structure of
           | the codebase described in the Google writeup make this theory
           | less likely; building an exploit toolkit while using these
           | practices to cosplay as a US-government affiliated engineer
           | would be clever and fun, but it's not something we've really
           | seen before.
           | 
           | * This toolkit originated from (whether it was leaked,
           | compromised, or resold) the same actor who was responsible
           | for Operation Triangulation.
        
             | tptacek wrote:
             | Right, I agree with you; my thing is mostly just
             | differentiating between CNE enablement packages the USG
             | itself creates vs CNE enablement packages that are on offer
             | to every USG-aligned country, of which there are a bunch.
        
         | Simulacra wrote:
         | Good point, that was also struck by the comment that it's
         | infected "tens of thousands" phones. That's a minuscule
         | rounding error.
        
         | dang wrote:
         | The title limit is 80 chars, if anyone wants to figure out a
         | decent way to squeeze possibility back in there.
        
           | alwa wrote:
           | "Possible US-Gov-made iPhone-hacking toolkit is now in
           | foreign and criminal hands" ?
        
             | dang wrote:
             | We try to avoid abbreviations if possible. You spurred me
             | to take another crack at it and I think it worked this
             | time? Happy to edit again if not...
        
           | irishcoffee wrote:
           | A US Govt iPhone-hacking suite is now possibly in criminal
           | hands
           | 
           | 15 chars to spare!
        
             | dang wrote:
             | I think the "possibly" is supposed to mean "possibly
             | produced by the US government"
        
               | irishcoffee wrote:
               | Good point.
        
       | doctorpangloss wrote:
       | the government doesn't have superpowerful code crackers though
       | 
       | it has a guy working at apple who introduces the subtle
       | vulnerability he is instructed to do
        
         | tptacek wrote:
         | I expect the evidence for this claim is axiomatic, which is to
         | say that you think it sounds good.
        
           | lightedman wrote:
           | No, anyone who remembers the Best Buy/FBI debacle knows that
           | this statement is very well-grounded in reality. If you took
           | your laptop to Best Buy for repairs, the FBI got a copy of
           | your hard drive contents.
        
             | majorchord wrote:
             | Source:
        
           | doctorpangloss wrote:
           | haha yeah, thanks for the compliment
        
           | joshrw wrote:
           | Hello, have you heard of the Snowden revelations? What OP was
           | referring to are called bugdoors.
        
         | thesuitonym wrote:
         | Those two are not mutually exclusive.
        
         | 8cvor6j844qw_d6 wrote:
         | Yeah. TAO was intercepting Cisco routers in transit and
         | installing implants.
         | 
         | The leap from supply chain interdiction to cooperative insiders
         | isn't a big one.
        
       | everdrive wrote:
       | No matter the risk, I must carry my smartphone everywhere and
       | install every app. It would be unimaginable to have the urge to
       | look something up, but then wait to do it later until I'm using a
       | real computer. No negative outcome will EVER shake my deep,
       | permanent need to carry a smartphone all the time and use it for
       | as much as possible.
        
         | theearling wrote:
         | Webapps exist for a reason, they don't get all the special
         | permissions apps get when fully installed.
         | 
         | at the very least use a VPN / more secure phone like a pixel
         | with graphene
         | 
         | You keep doing you though
        
           | thewebguyd wrote:
           | Ironically, the exploits in this leaked kit all involved
           | flaws in webkit, so you'd have been safer sticking to native
           | apps assuming they didn't have any webviews in them to load
           | the malicious site.
        
             | SpaceManNabs wrote:
             | WebView is the worst experience I have on any smart phone
             | or mobile app.
             | 
             | The fact that there is no option so that any webview by
             | default opens in safari across all app in ios is horrible.
             | 
             | i am not surprised it is riddled with security holes.
        
           | thesuitonym wrote:
           | A VPN won't help you if your device is compromised. A VPN
           | won't help you if the server is compromised. A VPN won't help
           | you if the VPN is compromised.
           | 
           | I really wish people would understand that VPNs are not
           | magical, unbreakable security. VPNs are barely security at
           | all, and commercial VPNs even less so.
        
             | theearling wrote:
             | oh 100% agree here, I was just confused at the OP comments
             | evangelism of installing and keeping his phone on his for
             | those quick fix google searches
        
       | stock_toaster wrote:
       | With this administration? Color me unsurprised.
        
       ___________________________________________________________________
       (page generated 2026-03-03 23:00 UTC)