Spyware Vendors Caught Exploiting Zero-Day Vulnerabilities on Android and iOS Devices

March 29, 2023Rabbi LakshmananZero-day/mobile security

Zero-day vulnerability

Google’s Threat Analysis Group (TAG) has revealed that a number of zero-day vulnerabilities addressed last year were exploited by commercial spyware vendors to target Android and iOS devices.

Two different campaigns were limited and targeted, taking advantage of the patch gap between the release of the fix and its actual deployment to the targeted devices.

TAG’s Clement Lecigne said in a new report, “These vendors enable the proliferation of dangerous hacking tools, arming governments that cannot develop these capabilities in-house.

“While the use of surveillance technology may be legal under national or international law, it can be used by governments to target dissidents, journalists, human rights activists and opposition politicians. There are often.”

The first of the two operations took place in November 2022 and involved sending shortened links in SMS messages to users located in Italy, Malaysia and Kazakhstan.

Upon clicking the URL, the recipient was redirected to a web page hosting an Android or iOS exploit, and then redirected again to a legitimate news or shipment tracking website.

The iOS exploit chain leveraged multiple bugs, including CVE-2022-42856 (zero-day at the time), CVE-2021-30900, and Pointer Authentication Code (PAC) bypass to install .IPA files on affected devices. bottom.

The Android exploit chain consisted of three exploits, CVE-2022-3723, CVE-2022-4135 (zero-day exploitation), and CVE-2022-38181, delivering unspecified payloads.

CVE-2022-38181 is a privilege escalation bug affecting the Mali GPU kernel driver and was patched by Arm in August 2022, although attackers had already exploited this flaw before the patch was released. I don’t know if he owned it.

Another thing to note is that Android users who clicked the link and opened it in the Samsung Internet Browser were redirected to Chrome using a method called Intent Redirection.

A second campaign observed in December 2022 consisted of multiple zero-day and n-days targeting the latest version of the Samsung Internet Browser, with exploits linked once via SMS to devices located in the UAE. was delivered as

webinar

Discover the hidden dangers of third-party SaaS apps

Are you aware of the risks associated with third-party app access to your company’s SaaS apps? Join our webinar to learn about the types of permissions granted and how to minimize the risks.

reserve a seat

The webpage is similar to one used by Spanish spyware company Variston IT, which ended up embedding a C++-based malicious toolkit capable of gathering data from chat and browser applications. .

The exploited flaws are CVE-2022-4262, CVE-2022-3038, CVE-2022-22706, CVE-2023-0266, and CVE-2023-26083. The exploit chain is believed to have been used by a customer or partner of Variston IT.

However, the scale and target nature of the two campaigns are unknown at this time.

This fact comes just days after the US government issued an executive order limiting the use of commercial spyware that poses a national security risk to federal agencies.

“These campaigns are a reminder that the commercial spyware industry continues to thrive,” said Lecigne. “Even small surveillance vendors have access to zero-day vulnerabilities. Vendors that covertly stockpile and use zero-day vulnerabilities pose serious risks to the Internet.”

“These campaigns may also indicate that exploits and techniques are shared among surveillance vendors, enabling the spread of dangerous hacking tools.”

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *