POISON_CARP__2020__Evil_Eye_Threat_Actor_Resurfaces_with_iOS_Exploit_and_Updated_Implant.pdf
ID: ffe2b10f-55ee-4705-bd3d-005e25cb2465
STIX ID: report--ffe2b10f-55ee-4705-bd3d-005e25cb2465
Threat Score
88/100
Uploaded: 2026-08-19
Published Date: 2020-04-22
Last Modified Date: 2020-04-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Volexity documents the resurgence of the Evil Eye threat actor using the IRONSQUIRREL framework to deliver an undocumented iOS WebKit exploit against iOS 12.3/12.3.1/12.3.2; successful exploitation drops the INSOMNIA implant which runs as root, exfiltrates data (including Signal and ProtonMail artifacts), performs HTTPS C2 communication with embedded certificate validation, and is distributed via compromised Uyghur-focused websites—appendices include C2 IPs, hostnames, malware hashes, and embedded certificate details.
