Google Says ISPs Helped Attackers Infect Targeted Smartphones with Hermit Spyware
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-4344 | Memory Corruption Flaw in Apple iOS, macOS, tvOS, and watchOS (Pre-2018 Releases) CVE-2018-4344 is a memory corruption vulnerability (CWE-119) in Apple's operating systems that was fixed with improved memory handling in the Fall 2018 releases. It carries a local attack vector with user interaction required (CVSS AV:L/UI:R), meaning exploitation requires the victim to process attacker-supplied content, and successful exploitation yields high confidentiality, integrity, and availability impact, consistent with potential arbitrary code execution. Every user running versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 is affected, spanning iPhone/iPad, Mac, Apple TV, and Apple Watch. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2022-06-27, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use is listed as unknown. EPSS currently estimates a 2.9% probability of exploitation within 30 days (86th percentile). Do: Upgrade affected devices to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 or later per Apple's instructions, as required by the CISA KEV listing. Inventory your fleet for Apple devices running outdated OS versions; for hardware that cannot run iOS 12, treat the device as permanently unpatched and replace or isolate it. Because the flaw is confirmed exploited in the wild and appears in KEV, prioritize these updates in patch cycles, particularly on user workstations and BYOD endpoints. | 7.8 | 3% | KEV |
| masshundreds of millions of Apple devices ran iOS/macOS/tvOS/watchOS versions below the 2018 fixes at disclosure, with an unknown but likely substantial share… | |
| CVE-2019-8605 | Use-After-Free in Apple iOS, macOS, tvOS, watchOS Enables Privileged Code Execution CVE-2019-8605 is a use-after-free memory corruption flaw (CWE-416) affecting Apple's iOS, macOS (Mojave), tvOS, and watchOS, addressed with improved memory management in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1. It is triggered locally: a malicious application running on a device (the CVSS vector requires user interaction, meaning the victim must run the malicious app) exploits the stale-memory condition. A successful attack allows the application to execute arbitrary code with system privileges, i.e., a privilege escalation or sandbox escape beyond normal app permissions. Any iPhone, iPad, Mac, Apple TV, or Apple Watch running an OS version older than the fixed releases is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), indicating known in-the-wild exploitation, with a high EPSS score of ~17.5% (97th percentile) and no known public proof-of-concept. Do: Update iPhones/iPads to iOS 12.3 or later, Macs to macOS Mojave 10.14.5 or later, Apple TVs to tvOS 12.3 or later, and Apple Watches to watchOS 5.2.1 or later. Use MDM or endpoint inventory to identify devices still running older OS versions, prioritizing KEV-driven patching requirements. Until patched, limit exposure by installing applications only from trusted sources, since exploitation requires running a malicious local application. | 7.8 | 18% | KEV |
| masshundreds of millions of Apple devices ran affected OS versions at disclosure; devices remaining on pre-fix versions today are likely in the millions (exact… | |
| CVE-2020-3837 | Memory Corruption in Apple iOS, macOS, tvOS, watchOS Enables Kernel-Level Code Execution Apple patched an out-of-bounds write (CWE-787), a memory corruption flaw in kernel memory handling, across iOS/iPadOS, macOS Catalina, tvOS and watchOS. The flaw is triggered by a local application performing the faulty memory access, and the CVSS vector indicates user interaction (running the application) is required. A successful attacker can execute arbitrary code with kernel privileges, meaning full compromise of the affected device. Anyone running iPhone/iPad, Mac, Apple TV or Apple Watch software older than iOS/iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1 and watchOS 6.1.2 respectively is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), so exploitation has been observed in the wild, and EPSS assigns a 16.1% probability of exploitation within 30 days (97th percentile). Do: Update all Apple endpoints to the fixed releases: iOS and iPadOS 13.3.1 or later, macOS Catalina 10.15.3 or later, tvOS 13.3.1 or later, and watchOS 6.1.2 or later; apply per vendor instructions to satisfy the KEV required action. Inventory managed and BYOD Apple devices for OS versions below these builds and prioritize patching, since the flaw is KEV-listed and mobile spyware campaigns targeting iPhones are active (e.g., LightSpy, though no confirmed link to this CVE is in the data). Until devices are patched, limit installing applications from untrusted sources, as triggering requires running a local application. | 7.8 | 16% | KEV |
| masswell over 1 billion active Apple devices in the affected installed base (iPhone/iPad/Mac/Apple TV/Apple Watch) | |
| CVE-2020-9907 | Memory Corruption with Kernel Privileges in Apple iOS, iPadOS, and tvOS Apple patched a kernel memory corruption flaw (CWE-787, out-of-bounds write) in iOS 13.6, iPadOS 13.6, and tvOS 13.4.8 by removing the vulnerable code. The flaw is triggered locally: an application running on the device (local attack vector, user interaction required per the CVSS scoring) can corrupt kernel memory and execute arbitrary code with kernel privileges. A successful attacker gains the highest privilege level on the device, effectively escalating from an application to full kernel control. Anyone running an iPhone, iPad, or Apple TV on versions earlier than iOS/iPadOS 13.6 or tvOS 13.4.8 is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-06-27, indicating exploitation in the wild, though no public proof-of-concept is known and EPSS estimates a roughly 3.9% chance of exploitation in the next 30 days. Do: Upgrade iPhones and iPads to iOS/iPadOS 13.6 or later and Apple TV devices to tvOS 13.4.8 or later, per CISA's required action to apply vendor updates. Because the KEV listing confirms in-the-wild exploitation, prioritize patching and check current builds via Settings > General > Software Update. On unpatched devices, limit exposure by only installing trusted applications, since triggering the flaw requires an application running locally on the device. | 7.8 | 4% | KEV |
| masshundreds of millions of Apple devices at the time of disclosure (subset of the iOS/iPadOS installed base on pre-13.6 builds, plus legacy Apple TV units) | |
| CVE-2021-30883 | Kernel Memory Corruption Zero-Day in Apple iOS, iPadOS, macOS, tvOS, watchOS CVE-2021-30883 is a memory corruption flaw (CWE-787, out-of-bounds write) in the kernel of Apple's iOS, iPadOS, macOS, tvOS, and watchOS, addressed with improved memory handling. It is triggered by a local application that mishandles memory, with the CVSS vector (AV:L, UI:R) indicating a user must run or interact with the malicious app. Successful exploitation allows arbitrary code execution with kernel privileges, giving an attacker full control over the affected device. All users of iPhones, iPads, Macs, Apple TVs, and Apple Watches running versions earlier than the patched releases are affected. Apple acknowledged the issue may have been actively exploited in the wild, and CISA added it to the KEV catalog; related reporting indicates it was among 2021 zero-days developed commercially and sold to government clients. Do: Upgrade iPhones and iPads to iOS/iPadOS 15.0.2 (or 14.8.1 for devices staying on iOS 14), Macs to macOS Monterey 12.0.1 or Big Sur 11.6.1, Apple TVs to tvOS 15.1, and Apple Watches to watchOS 8.1. As a CISA KEV entry, the required action is to apply updates per vendor instructions; inventory managed Apple devices and verify OS versions to confirm patching, prioritizing high-risk users who may have been targeted by commercial spyware. | 7.8 | 15% | KEV |
| mass≈1 billion+ Apple devices (iPhone/iPad/Mac/Apple TV/Apple Watch installed base running the affected OS versions) | |
| CVE-2021-30983 | Kernel Buffer Overflow in Apple iOS and iPadOS Enables Arbitrary Code Execution CVE-2021-30983 is a buffer overflow (CWE-120) in Apple iOS and iPadOS, caused by improper memory handling, that was corrected in iOS 15.2 and iPadOS 15.2. It is triggered locally by an application running on the device (CVSS local attack vector with user interaction), so a user must run a malicious or compromised app for the flaw to be reached. Successful exploitation allows that application to execute arbitrary code with kernel privileges, giving the attacker near-complete control of the affected iPhone or iPad. Anyone using an iPhone or iPad running a version earlier than iOS/iPadOS 15.2 is affected. The vulnerability is confirmed exploited in the wild, having been added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-27, with EPSS estimating a 2.9% probability of exploitation within 30 days; no public proof-of-concept is known. Do: Upgrade all iPhones and iPads to iOS 15.2 or iPadOS 15.2 or later per Apple's instructions, as this is the required action in CISA's KEV catalog. Use MDM or device inventory to identify any devices still below 15.2 and prioritize them for patching; until updated, limit app installation from untrusted sources, since exploitation requires running an application on the device. | 7.8 | 3% | KEV |
| masshundreds of millions of iPhone/iPad devices (Apple's active installed base exceeds 1 billion; every device not yet updated to iOS/iPadOS 15.2 is affected) |
Full article1,052 words · extracted from thehackernews.com · click to collapse
A week after it emerged that a sophisticated mobile spyware dubbed Hermit was used by the government of Kazakhstan within its borders, Google said it has notified Android users of infected devices.
Additionally, necessary changes have been implemented in Google Play Protect — Android's built-in malware defense service — to protect all users, Benoit Sevens and Clement Lecigne of Google Threat Analysis Group (TAG) said in a Thursday report.
Hermit, the work of an Italian vendor named RCS Lab, was documented by Lookout last week, calling out its modular feature-set and its abilities to harvest sensitive information such as call logs, contacts, photos, precise location, and SMS messages.
Once the threat has thoroughly insinuated itself into a device, it's also equipped to record audio and make and redirect phone calls, besides abusing its permissions to accessibility services on Android to keep tabs on various foreground apps used by the victims.
Its modularity also enables it to be wholly customizable, equipping the spyware's functionality to be extended or altered at will. It's not immediately clear who were targeted in the campaign, or which of RCS Lab clients were involved.
The Milan-based company, operating since 1993, claims to provide "law enforcement agencies worldwide with cutting-edge technological solutions and technical support in the field of lawful interception for more than twenty years." More than 10,000 intercepted targets are purported to be handled daily in Europe alone.
"Hermit is yet another example of a digital weapon being used to target civilians and their mobile devices, and the data collected by the malicious parties involved will surely be invaluable," Richard Melick, director of threat reporting for Zimperium, said.
The targets have their phones infected with the spy tool via drive-by downloads as initial infection vectors, which, in turn, entails sending a unique link in an SMS message that, upon clicking, activates the attack chain.
It's suspected that the actors worked in collaboration with the targets' internet service providers (ISPs) to disable their mobile data connectivity, followed by sending an SMS that urged the recipients to install an application to restore mobile data access.
"We believe this is the reason why most of the applications masqueraded as mobile carrier applications," the researchers said. "When ISP involvement is not possible, applications are masqueraded as messaging applications."
To compromise iOS users, the adversary is said to have relied on provisioning profiles that allow fake carrier-branded apps to be sideloaded onto the devices without the need for them to be available on the App Store. Apple, following disclosure, has moved to revoke all known accounts and certificates associated with the nefarious operation.
"Enterprise certificates are meant only for internal use by a company, and are not intended for general app distribution, as they can be used to circumvent App Store and iOS protections," the Cupertino-based company said in an October report about sideloading. "Despite the program's tight controls and limited scale, bad actors have found unauthorized ways of accessing it, for instance by purchasing enterprise certificates on the black market."
An analysis of the iOS version of the app shows that it leverages as many as six exploits — CVE-2018-4344, CVE-2019-8605, CVE-2020-3837, CVE-2020-9907, CVE-2021-30883, and CVE-2021-30983 — to exfiltrate files of interest, such as WhatsApp databases, from the device.
"As the curve slowly shifts towards memory corruption exploitation getting more expensive, attackers are likely shifting too," Google Project Zero's Ian Beer said in a deep-dive analysis of an iOS artifact that impersonated the My Vodafone carrier app.
On Android, the drive-by attacks require that victims enable a setting to install third-party applications from unknown sources, doing so which results in the rogue app, masquerading as smartphone brands like Samsung, requests for extensive permissions to achieve its malicious goals.
The Android variant, besides attempting to root the device for entrenched access, is also wired differently in that instead of bundling exploits in the APK file, it contains functionality that permits it to fetch and execute arbitrary remote components that can communicate with the main app.
"This campaign is a good reminder that attackers do not always use exploits to achieve the permissions they need," the researchers noted. "Basic infection vectors and drive by downloads still work and can be very efficient with the help from local ISPs."
Stating that seven of the nine zero-day exploits it discovered in 2021 were developed by commercial providers and sold to and used by government-backed actors, the tech behemoth said it's tracking more than 30 vendors with varying levels of sophistication who are known to trade exploits and surveillance capabilities.
What's more, Google TAG raised concerns that vendors like RCS Lab are "stockpiling zero-day vulnerabilities in secret" and cautioned that this poses severe risks considering a number of spyware vendors have been compromised over the past ten years, "raising the specter that their stockpiles can be released publicly without warning."
"Our findings underscore the extent to which commercial surveillance vendors have proliferated capabilities historically only used by governments with the technical expertise to develop and operationalize exploits," TAG said.
"While use of surveillance technologies may be legal under national or international laws, they are often found to be used by governments for purposes antithetical to democratic values: targeting dissidents, journalists, human rights workers and opposition party politicians."
Update: When reached for comment, RCS Lab said its "core business is the design, production and implementation of software platforms dedicated to lawful interception, forensic intelligence, and data analysis" and that it helps law enforcement prevent and investigate serious crimes such as acts of terrorism, drug trafficking, organized crime, child abuse, and corruption.
Here is the rest of the unattributed statement -
RCS Lab exports its products in compliance with both national and European rules and regulations. Any sales or implementation of products is performed only after receiving an official authorization from the competent authorities. Our products are delivered and installed within the premises of approved customers. RCS Lab personnel are not exposed, nor participate in any activities conducted by the relevant customers. RCS Lab strongly condemns any abuse or improper use of its products which are designed and produced with the intent of supporting the legal system in preventing and combating crime.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/06/google-says-isps-helped-attackers.html