ZeroHour
The Recordpublished ()ingested

Windows spyware and zero-days linked to prodigious Israeli hack-for

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21166
Race Condition Heap Corruption in Google Chromium (Chrome, Edge, Opera)

Google Chromium contains a race condition (CWE-362) that can lead to heap corruption (CWE-122) when the browser processes a crafted HTML page, meaning an attacker can trigger the flaw simply by getting a user to visit an attacker-controlled or malicious webpage. Successful exploitation of the heap corruption could crash the browser and potentially allow the attacker to execute code within the affected browser process. Because the vulnerable code is in the Chromium engine itself, all Chromium-based browsers are potentially affected, including Google Chrome, Microsoft Edge, Opera, and other derived browsers, across desktop and mobile fleets. CISA added CVE-2021-21166 to the Known Exploited Vulnerabilities catalog on 2021-11-03, confirming the flaw is being exploited in the wild, though ransomware use is unknown and no public proof-of-concept is available. EPSS currently assigns a 26.7% probability of exploitation within 30 days (98th percentile), and CVSS scoring has not yet been published.

Do: Apply the latest patched releases of all Chromium-based browsers in use (Chrome, Edge, Opera, and any derived browsers) per vendor instructions, as required by CISA's KEV listing. Prioritize managed endpoints and any systems where users browse untrusted or internet-facing websites, verify fleet-wide browser versions after updating, and monitor CISA/vendor advisories for ransomware-associated activity since that linkage is currently unknown.

8.827% KEV
  • Google Chromium
  • Google Chrome (Chromium-based)
  • Microsoft Edge (Chromium-based)
  • +2 more
massbillions of users and installations (Chromium powers Chrome, Edge, Opera and many other browsers)
CVE-2021-30551
V8 Type Confusion Zero-Day in Google Chrome (CVE-2021-30551), Exploited in the Wild

CVE-2021-30551 is a type confusion flaw (CWE-843) in the V8 JavaScript engine used by Google Chrome and Chromium, which can lead to heap corruption. An attacker triggers it by persuading a user to open a specially crafted HTML page — the browser bug requires user interaction but no privileges or authentication. Successful exploitation could allow a remote attacker to execute code or otherwise corrupt the browser process, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Anyone running Google Chrome prior to 91.0.4472.101, including Chromium-based packages such as Fedora's chromium, is affected. The flaw was exploited as a zero-day before the fix was released, with Google attributing recent Chrome zero-day attacks including this issue to campaigns against Armenian targets linked to a commercial spyware vendor, and it is listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Update Google Chrome to 91.0.4472.101 or later (via chrome://settings/help) and update Fedora's chromium package to the patched build, then verify the version in chrome://version. Fedora/Chromium administrators should apply vendor updates per CISA KEV guidance. Until patched, treat web browsing as a risk vector and avoid opening untrusted links, since exploitation requires loading a crafted web page.

8.865% KEV PoC
  • google chrome Google Chrome prior to 91.0.4472.101 (all platforms)
  • google chromium (V8 engine) Chromium builds with the vulnerable V8 engine, prior to the fix shipped in Chrome 91.0.4472.101
  • fedoraproject fedora (chromium package) Fedora chromium builds prior to the 91.0.4472.101-equivalent update
masshundreds of millions to billions of Chrome/Chromium installs worldwide (Chrome is the world's dominant browser)
CVE-2021-33771
+1 in the same advisory: …31979
Privilege Escalation in Microsoft Windows Kernel Exploited in the Wild (CVE-2021-33771)

CVE-2021-33771 is a high-severity (CVSS 3.1: 7.8) elevation-of-privilege flaw in the Windows kernel that allows a low-privileged user who can already execute code on a local machine to escalate to kernel-level (SYSTEM) privileges, with high impact on confidentiality, integrity and availability and no user interaction required. It is triggered locally, for example by running a malicious process or planted component on an affected system, and because it grants full SYSTEM rights it is typically chained with another flaw (such as a browser or document exploit) to escape a sandbox or complete an intrusion. Affected products span every mainstream Windows release current at disclosure: Windows 10 versions 1507, 1607, 1809, 1909, 2004, 20H2 and 21H1, Windows 8.1 and Windows RT 8.1, and Windows Server 2004, 2012 and 2016. The flaw was exploited before a patch existed; it was fixed in Microsoft's July 2021 Patch Tuesday (reported as 117 flaws including 9 zero-days, 4 actively exploited) and was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, with EPSS in the 95th percentile (~10% probability of exploitation within 30 days). Related coverage links the Windows zero-days patched in July 2021 to spyware operations by the Israeli surveillance vendor Candiru targeting journalists and activists, indicating targeted in-the-wild use rather than mass commodity exploitation.

Do: Apply Microsoft's July 2021 (or later) cumulative security updates to all affected Windows 10, 8.1, RT 8.1 and Windows Server hosts and verify the kernel update is installed, prioritizing KEV-driven remediation. Given the reported use in targeted spyware campaigns against journalists and activists, hunt on systems that ran unpatched builds for signs of compromise, such as unexpected process creation by low-privileged users, novel persistence, or unusual outbound traffic.

7.810% KEV
  • microsoft Windows 10 version 1507 builds prior to the July 2021 security update
  • microsoft Windows 10 version 1607 builds prior to the July 2021 security update
  • microsoft Windows 10 version 1809 builds prior to the July 2021 security update
  • +9 more
masshundreds of millions to 1 billion+ Windows devices and servers
CVE-2021-33742
Out-of-Bounds Write RCE in Microsoft Windows MSHTML Engine (CVE-2021-33742)

A remote code execution vulnerability exists in the Microsoft Windows MSHTML Platform — the Internet Explorer/Trident rendering engine that Windows components and applications invoke to display web content — caused by an out-of-bounds write (CWE-787). An attacker triggers it by persuading a user to open attacker-controlled content, such as a crafted document or web page that causes MSHTML to render a remote URL; no privileges are required, but user interaction is needed and the attack is rated high complexity. Successful exploitation runs attacker code in the context of the logged-in user, potentially allowing installation of programs, viewing/changing/deleting data, or creating new accounts with the victim's rights. The affected range spans Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 21H1, and Windows Server 2008 and 2012 — essentially the entire supported Windows installed base at the time of disclosure. Exploitation is confirmed in the wild: Microsoft disclosed the flaw as used in limited targeted attacks, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), and EPSS assigns a 59.4% 30-day exploitation probability (99th percentile).

Do: Apply Microsoft's security update for CVE-2021-33742, delivered via the July 2021 cumulative Windows updates (and later), to all affected Windows 7/8.1/RT 8.1/10 clients and Windows Server 2008/2012 hosts, prioritizing internet-exposed systems and per CISA's required action. Because exploitation requires user interaction, treat unsolicited documents and links with caution until systems are patched. No public proof-of-concept is known, but the KEV listing confirms real-world targeted exploitation, so assume active scanning/attacks and verify patch status across the estate.

7.559% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • Microsoft Windows 7 all supported editions (as listed by CISA)
  • Microsoft Windows 8.1 all supported editions (as listed by CISA)
  • +3 more
masson the order of 1 billion+ Windows installations
Full article687 words · extracted from therecord.media · click to collapse

Microsoft and Citizen Lab said today that an Israeli company named Candiru is behind two Windows zero-day exploits that have been used to infect and deploy a never-before-seen spyware strain on the devices of at least 100 victims, including politicians, human rights activists, journalists, academics, embassy workers and political dissidents.

Founded in 2014, the company is part of Israel's burgeoning cybersecurity scene, where it has provided offensive capabilities to governments across the world.

While the company's hack-for-hire offerings have been known for years, the company and its capabilities have remained largely unknown.

Boasting of being able to infect and monitor iPhones, Androids, Macs, PCs, and cloud accounts, the two reports released today by Microsoft and Citizen Lab are the first to ever describe in great technical depth one of the company's hacking tools.

Candiru linked to DevilsEye malware, several zero-days

Named DevilsEye, this tool is a Windows malware strain with spyware capabilities that can allow Candiru's clients full access to an infected device once the tool has been deployed on a target's Windows system.

The existence of this spyware was first discovered by security researchers from the University of Toronto's Citizen Lab while conducting a forensic investigation on the device of "a politically active victim in Western Europe."

Sharing their findings with Microsoft, the OS maker was able to use its extensive telemetry database and uncover at least 100 victims infected with DevilsEye in countries such as Palestine, Israel, Iran, Lebanon, Yemen, Spain, United Kingdom, Turkey, Armenia, and Singapore.

See the Microsoft and Citizen Lab reports for a technical breakdown of the DevilsEye malware.

Microsoft said that the spyware was typically deployed by luring victims on websites hosting an exploit kit that abused browser vulnerabilities to plant the malware on a victim's device, where it subsequently abused a second-stage Windows exploit to gain admin-level access for its operators.

The attack chain was highly advanced and used never-before-seen vulnerabilities, known as zero-days in the cybersecurity community.

These included two Chrome zero-days (CVE-2021-21166 and CVE-2021-30551), an Internet Explorer one (CVE-2021-33742), and two in the Windows OS (CVE-2021-31979 and CVE-2021-33771).

All vulnerabilities have been patched at the time of today's reports.

The first three zero-days are also the same listed in a Google report published on Wednesday in which the search giant's security teams linked the Chrome and IE exploits to an unnamed commercial surveillance company. Google said the zero-days were sold to at least two state-sponsored threat actors, which abused them in attacks against Armenian targets. In an update today, Google also attributed the zero-days to Candiru.

Hundreds of Candiru domains still active

However, the Citizen Lab team said that Candiru's hacking-for-hire capabilities are far larger than what can be gleaned from Google and Microsoft's report.

Citizen Lab analysts said they found more than 750 domains that hosted Candiru spyware, including large clusters in the UAE and Saudi Arabia, which suggests the two countries are some of the company's bigger customers.

Some of these domains masqueraded as advocacy organizations such as Amnesty International, the Black Lives Matter movement, as well as media companies, and other civil-society-themed entities, suggesting that the attacks were mostly aimed against activists rather than unmasking criminal groups.

In a separate blog post on Thursday, Cristin Goodwin - General Manager, Digital Security Unit, echoed Microsoft's previous call to action against companies like Candiru, which have been observed selling cyber arms to abusive regimes for years. These governments have often been seen using these hacking tools against civil society members instead of espionage or tracking criminals.

Microsoft previously called that cyber arms dealers should not have immunity for their actions when their tools are used for human rights abuses.

Candiru could not be contacted for comment as the company's past domains returned errors today.

Goodwin also said that Microsoft also deployed protections against Candiru's malware.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/windows-spyware-and-zero-days-linked-to-prodigious-israeli-hack-for-hire-company