logo

POISON_CARP__2020__Evil_Eye_Threat_Actor_Resurfaces_with_iOS_Exploit_and_Updated_Implant.pdf

ID: ffe2b10f-55ee-4705-bd3d-005e25cb2465

STIX ID: report--ffe2b10f-55ee-4705-bd3d-005e25cb2465

Threat Score

88/100

Uploaded: 2026-08-19

Published Date: 2020-04-22

Last Modified Date: 2020-04-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Volexity documents the resurgence of the Evil Eye threat actor using the IRONSQUIRREL framework to deliver an undocumented iOS WebKit exploit against iOS 12.3/12.3.1/12.3.2; successful exploitation drops the INSOMNIA implant which runs as root, exfiltrates data (including Signal and ProtonMail artifacts), performs HTTPS C2 communication with embedded certificate validation, and is distributed via compromised Uyghur-focused websites—appendices include C2 IPs, hostnames, malware hashes, and embedded certificate details.