Experts spotted the iOS version of the Exodus surveillance app
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-5195 | Dirty COW Race Condition Enables Local Privilege Escalation in the Linux Kernel CVE-2016-5195, widely known as 'Dirty COW', is a race condition (CWE-362) in the copy-on-write (COW) memory-handling code in mm/gup.c of the Linux kernel, affecting kernel versions 2.x through 4.x before 4.8.3. A local user with low privileges can trigger the race — including via the PTRACE_POKEDATA path used in public exploits — to write to a read-only memory mapping that should not be writable, corrupting files or overwriting memory. This yields root-level privileges on the host, enabling full system takeover, malware implantation and persistence. Any system running an affected kernel is exposed, spanning Ubuntu, Red Hat Enterprise Linux (including AUS, EUS, Long Life and TUS variants), Debian, Fedora, Palo Alto Networks PAN-OS, and NetApp Cloud Backup and HCI Storage Nodes that ship an affected kernel. Exploitation is confirmed in the wild: the flaw was actively exploited in October 2016, including by the first Android malware found using it to gain root, it was added to CISA's KEV catalog on 2022-03-03 with the required action to apply vendor updates, and EPSS currently assigns an 83.5% probability of exploitation in the next 30 days (100th percentile). Do: Upgrade to Linux kernel 4.8.3 or later, or apply the vendor-issued patched/backported kernel updates from Canonical, Red Hat, Debian, Fedora Project, Palo Alto Networks (PAN-OS) and NetApp, per the CISA KEV required action. Prioritize unpatched legacy servers and internet-exposed Linux hosts — especially multi-user systems, SSH-accessible machines and containers where untrusted users can run code — and update Android devices that may have been silently rooted via Dirty COW. Until patching completes, restrict local and SSH access to trusted users, since exploitation requires local low-privileged code execution. | 7.0 | 84% | KEV PoC ×5 |
| mass≈ hundreds of millions of Linux systems and devices (affected kernels shipped in nearly all mainstream distributions, appliances and Android devices of the… |
Full article610 words · extracted from securityaffairs.com · click to collapse

In the last weeks, a new Android surveillance malware dubbed Exodus made the headlines, now expert found the iOS version of the government spyware.
Security experts at LookOut have discovered an iOS version of the dreaded surveillance Android app Exodus that was initially found on the official Google Play Store.
Exodus for Android is a three-stage malware, the first is a small dropper that collected basic device information (i.e. IMEI, phone number).
The second stage is composed of multiple binary packages that deploy a well-implemented suite of surveillance functionalities, and the finals stage leverages the DirtyCOW exploit (CVE-2016-5195) to gain root privileges on the device and install the Exodus app.
Lookout first spotted the sophisticated Android surveillance software early last year.
Early versions of Exodus app used infrastructure which belonged to a company named Connexxa S.R.L. and were signed using the name of a developer who seems to hold equity in Connexxa.
The developer is also associated with a company called eSurv S.R.L., and many people claim the guy is working at this company.
“eSurv was a business unit of Connexxa and was leased to eSurv S.R.L in 2014. The business unit and the eSurv software and brand was sold from Connexxa S.R.L. to eSurv S.R.L. on Feb 28, 2016.”
The iOS version of Exodus has not been distributed through the official Apple App store, experts discovered that the surveillance malware was delivered through phishing websites that look like the ones of Italian and Turkmenistani mobile carriers.
“Analysis of these Android samples led to the discovery of infrastructure that contained several samples of an iOS port. So far, this software (along with the Android version) has been made available through phishing sites that imitated Italian and Turkmenistani mobile carriers.” reads the analysis published by Lookout.

Since on Apple devices it is not possible to directly install apps that are not present in the official app store, this new iOS version of Exodus is abusing the Apple Developer Enterprise program, which allows enterprises to distribute their own apps directly to their employees without passing through the App Store.
The phishing sites used to deliver the threat contained links to a distribution manifest, which contained metadata such as the application name, version, icon, and a URL for the IPA file.
According to Lookou, all these packages used provisioning profiles with distribution certificates associated with the company Connexxa.
The iOS version of Exodus is less sophisticated than the Android one, but it is still perfect spyware with the ability to exfiltrate a broad range of information from iPhone devices (i.e. contacts, audio recordings, photos, videos, GPS location, and device information).
The spyware exfiltrates data via HTTP PUT, experts pointed out that iOS and Android versions have the same command and control infrastructure and use similar communications protocols.
“Upload data was queued and transmitted via HTTP PUT requests to an endpoint on the C2. The iOS apps leverage the same C2 infrastructure as the Android version and use similar communications protocols. Push notifications were also used to control audio recording.” continues the analysis.
“Lookout has shared information about this family with Apple, and they have revoked the affected certificates. As a result, no new instances of this app can be installed on iOS devices and existing installations can no longer be run.”
Lookout researchers believe Exodus is a malware developed for governmet and law enforcement agencies, it is the result of a well-funded development effort.
At the time of writing, the experts have no idea of the number of iPhones devices infected by the iOS Exodus variant.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Exodus, iOS)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/83538/malware/exodus-ios-surveillance-app.html