ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Russian Hackers Use Commercial Spyware Exploits to Target Victims

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-41993
WebKit Code Execution Flaw in Apple iOS, iPadOS, macOS, and Safari

Apple's WebKit engine, which renders web content for Safari and for essentially all HTML processing on iOS, iPadOS, and macOS, contains a flaw that leads to code execution when processing maliciously crafted web content. It is triggered when a user's browser or embedded web view loads attacker-controlled web content, so simply visiting a hostile page can be enough. Successful exploitation could allow arbitrary code execution within the affected application's context, a common stepping stone to broader device compromise. All users of Apple iOS, iPadOS, macOS, and Safari are potentially affected, as are users of non-Apple products that rely on WebKit for HTML processing. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-25, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known.

Do: Apply Apple's latest security updates for iOS, iPadOS, macOS, and Safari that patch WebKit, following the vendor instructions referenced by the CISA KEV entry, and treat unpatched WebKit builds as actively exploited. Until systems are patched, restrict exposure to untrusted web content (e.g., limit browsing and in-app web views to trusted sites for high-risk users). Also inventory any non-Apple applications or HTML-processing components in your environment that bundle WebKit and update them as their maintainers ship fixes.

8.829% KEV
  • Apple iOS (WebKit)
  • Apple iPadOS (WebKit)
  • Apple macOS (WebKit)
  • +2 more
mass1+ billion devices/users (WebKit ships in Safari and all web-content rendering on iOS, iPadOS, and macOS)
CVE-2024-4671
Use-After-Free Sandbox Escape in Google Chrome/Chromium

CVE-2024-4671 is a use-after-free (CWE-416) in the Visuals component of Google Chrome and Chromium, fixed in Chrome 124.0.6367.201. It is triggered via a crafted HTML page, but the attacker must already have compromised the browser's renderer process, so this flaw is typically chained with a renderer exploit rather than used standalone. Successful exploitation enables a sandbox escape, letting the attacker break out of Chrome's renderer sandbox and gain broader access to the system beyond the browser tab. All users of Google Chrome versions prior to 124.0.6367.201 are affected, and per CISA's CPE data, Fedora's packaged Chromium builds are also in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-05-13, indicating active exploitation in the wild; no public proof-of-concept is known, EPSS estimates an 8.3% chance of exploitation within 30 days (95th percentile), and ransomware association is unknown.

Do: Update Google Chrome to 124.0.6367.201 or later (verify via chrome://settings/help, since Chrome auto-updates may lag), and update Fedora's chromium package to the fixed build; CISA KEV requires federal agencies to apply the vendor fix on the mandated timeline. Because this sandbox escape must be chained with a renderer compromise, defenders should treat any unpatched Chrome deployment as exposed and confirm via EDR logs whether suspicious renderer-process activity occurred; enterprise admins should push the update through managed-browser channels immediately.

9.68% KEV
  • google chrome prior to 124.0.6367.201
  • fedoraproject fedora packaged Chromium builds prior to the 124.0.6367.201 fix
mass≈3+ billion Chrome/Chromium users worldwide (Chrome holds roughly 65% of desktop browser market share, with additional exposure via Chromium packaged in Fedora)
CVE-2024-5274
Google Chrome V8 Type Confusion Allows In-Sandbox RCE via Crafted HTML Pages

CVE-2024-5274 is a type confusion flaw (CWE-843) in the V8 JavaScript engine of Google Chrome prior to 125.0.6422.112. A remote attacker can trigger it by persuading a user to open or interact with a crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code inside the browser's sandbox, and the scope-changed CVSS scoring indicates potential impact beyond the browser process itself. Anyone running an affected Chrome or Chromium build, including Chromium-derived distributions such as Fedora's Chromium package, is exposed. The flaw was added to CISA's KEV on 2024-05-28, a public PoC reference exists, and related news reports describe it as actively exploited in the wild.

Do: Upgrade Google Chrome to 125.0.6422.112 or later and confirm the build via chrome://version; Fedora users and users of Chromium-derived browsers should install the corresponding updated packages from their vendor. Because the flaw is listed in CISA KEV, federal agencies and targeted organizations must apply the vendor fix or discontinue use per the required action, and all users should avoid untrusted web content until patched.

9.67% KEV PoC
  • Google Chrome (Chromium V8 engine) all versions prior to 125.0.6422.112
  • Fedora Project Fedora (Chromium browser package) versions shipping a vulnerable V8 engine; fixed version not specified in available data
masson the order of billions of users (Chrome has 3+ billion users and roughly two-thirds desktop browser share)

Indicators of compromiseAll →

TypeIndicatorContext
domaingov.mnSafari and Google Chrome The hacker compromised the cabinet.gov[.]mn website from November 2023 and the mfa.gov[.]mn website f
Full article363 words · extracted from infosecurity-magazine.com · click to collapse

In a world-first, a Russian state-sponsored hacking group has used software vulnerability exploits “identical or strikingly similar” to ones previously used by NSO Group and Intellexa, two infamous commercial spyware vendors.

In a new report, Google Threat Analysis Group (TAG) shared insights on two watering hole attacks targeting Mongolian government websites between November 2023 and July 2024.

A watering hole is a website or platform frequented by a specific target group that hackers use to distribute malware or exploit vulnerabilities.

Google assessed “with moderate confidence” that the campaigns were conducted by the Russian-sponsored group APT29.

Watering Hole Attacks Targeting Safari and Google Chrome

The hacker compromised the cabinet.gov[.]mn website from November 2023 and the mfa.gov[.]mn website first in February 2024 and then in July 2024.

The campaigns took advantage of vulnerabilities in Apple’s Safari browser and Google Chrome on Android.

The first delivered an iOS WebKit exploit (via CVE-2023-41993) in order to steal user account cookies stored in Safari. This campaign affected iOS versions older than 16.6.1.

The second delivered a Chrome exploit chain (via CVE-2024-5274 and CVE-2024-4671) against Android users running versions from m121 to m123.

Although these vulnerabilities had already been fixed at the time the campaigns occurred, Google noted that they would still be effective against unpatched devices.

Exploits Previously Used by Spyware Vendors

Each of the three vulnerabilities had been exploited before by either NSO Group, an Israeli company developing Pegasus spyware, or Intellexa, a Greece-based firm that is part of a private consortium of surveillance solutions vendors and the maker of Predator spyware.

Exploit reuse timeline. Source: Google Threat Analysis Group
Exploit reuse timeline. Source: Google Threat Analysis Group

This is one of the first occurrences of a state-sponsored hacking group reusing commercial spyware vendors’ intrusion techniques.

“While we are uncertain how suspected APT29 actors acquired these exploits, our research underscores the extent to which exploits first developed by the commercial surveillance industry are proliferated to dangerous threat actors,” the report states.

The Google TAG team notified Apple, Alphabet’s Android and Google Chrome units and the the Mongolian computer emergency response team (CERT) about the campaigns at the time of discovery.

Read more: How to Mitigate Spyware Risks and Secure Your Business Secrets 

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/russian-hackers-spyware-exploits/