Malware
VALIDVICTOR
According to Google, this reconnaissance payload uses a profiling framework drawing canvas to identify the target’s exact iPhone model, a technique used by many other actors.
VALIDVICTOR is a iOS malware family operated by APT29.
Background
Per Google, this reconnaissance payload leans on a canvas-drawing profiling framework to pinpoint the victim's precise iPhone model, an approach shared by numerous other actors. It reports that model to the C2 along with the screen size, whether a touch screen is present, and a unique identifier tied to each initial GET request (for example, 1lwuzddaxoom5ylli37v90kj). The server responds with either an AES-encrypted next stage or a 0, the latter meaning no payload exists for that device. The payload then issues a further request to the exploit server with the parameter gcr=1 in order to obtain the AES decryption key from the C2.
Source: Malpedia (Fraunhofer FKIE).