SVR cyberspies used iOS zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-1879 | Universal XSS in Apple WebKit on iOS, iPadOS, and watchOS (Actively Exploited) CVE-2021-1879 is a universal cross-site scripting (UXSS) flaw in the WebKit browser engine affecting iOS, iPadOS, and watchOS, caused by an object-lifetime management error. An attacker can trigger it by convincing a user to process maliciously crafted web content (e.g., visiting an attacker-controlled page in Safari or another WebKit-based browser), allowing the attacker to bypass the same-origin policy and read or modify content of other sites in the browser. Successful exploitation is rated Medium severity (CVSS 6.1) because it requires user interaction, but it can leak sensitive data such as cookies, session tokens, or page content. Any user of an iPhone, iPad, or Apple Watch running software older than iOS 12.5.2, iOS 14.4.2/iPadOS 14.4.2, or watchOS 7.3.3 is affected. Apple reported that the issue may have been actively exploited in the wild at the time of patching, it is on the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), and public reporting tied its use to targeted campaigns (including Russian SVR-linked operations), though no public proof-of-concept is known. Do: Update devices to iOS 12.5.2 (older devices) or iOS 14.4.2/iPadOS 14.4.2, and Apple Watch devices to watchOS 7.3.3, per Apple's instructions. Because exploitation requires loading malicious web content in WebKit, avoid following untrusted web links on unpatched devices until updated; verify fleet-wide OS versions and confirm the fix, since this CVE is on the CISA KEV catalog with patching required. Check logs or browser history for signs of visits to attacker-controlled sites on devices that have since been updated, as no public proof-of-concept exists to test against. | 6.1 | 7% | KEV |
| masshundreds of millions of devices (Apple's active iPhone/iPad/watchOS install base was on the order of 1+ billion when patched; all unpatched devices are exposed… |
Full article444 words · extracted from therecord.media · click to collapse
The Russian hacking group that breached software provider SolarWinds in an infamous supply chain attack last year has returned to its regular skullduggery and, for the past few months, has conducted a massive spear-phishing operation aimed at government agencies, think tanks, consultants, and NGOs. Tracked as APT29 or Cozy Bear, the group has been linked by White House officials to the SVR, the Russian Foreign Intelligence Service. In reports published on Thursday by Microsoft and security firm Volexity, the two companies said the SVR hackers breached a Constant Contact marketing account belonging to USAID, a US government agency that provides help to foreign organizations. APT29 took control over the Constant Contact account and used it to send around 3,000 booby-trapped emails to more than 150 organizations across 24 countries. In the vast majority of emails, the hackers sent links to victims that redirected them to websites that used JavaScript code to drop a malicious ISO image file on their computers. If users opened the image file, a backdoor (Cobalt Strike beacon) would be installed on their systems that would ping the hackers in case of a successful compromise. But while using ISO files as a malware delivery system is quite rare, APT29 conducting spear-phishing attacks is not and has been their main modus operandi for the past decade. What was notable of the recent attacks was that in particular cases, the hackers filtered incoming users and directed iOS users to a special page where they deployed a Safari iOS zero-day bug to infect victims' devices. Tracked as CVE-2021-1879, Apple patched the zero-day in March after receiving an alert from Google's Threat Analysis Group. It is unclear if Google detected the same attacks, or the zero-day was used in a different campaign and then also reused by APT29. The recent APT29 attacks were discovered because the group abandoned the stealthy approach they had been using for months and launched a massive spear-phishing campaign on May 25, consisting of thousands of emails per day, which exposed their operations, according to Microsoft. My favorite part(s) are actually the months of testing/refinement leading up to the broad campaign
Jan: Firebase URL tracking user clicks - no payload
Feb: Firebase URL (tracking enabled) hosted ISO
Feb/Mar:
HTML -> ISO -> LNK -> CS
HTML -> ISO -> RTF -> CS
URL -> ISO -> …
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/svr-cyberspies-used-ios-zero-day-in-recent-phishing-campaign