ZeroHour
The Recordpublished ()ingested

Google says Russian group targeted Mongolian government with exploits used by NSO Group

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-1879
Universal XSS in Apple WebKit on iOS, iPadOS, and watchOS (Actively Exploited)

CVE-2021-1879 is a universal cross-site scripting (UXSS) flaw in the WebKit browser engine affecting iOS, iPadOS, and watchOS, caused by an object-lifetime management error. An attacker can trigger it by convincing a user to process maliciously crafted web content (e.g., visiting an attacker-controlled page in Safari or another WebKit-based browser), allowing the attacker to bypass the same-origin policy and read or modify content of other sites in the browser. Successful exploitation is rated Medium severity (CVSS 6.1) because it requires user interaction, but it can leak sensitive data such as cookies, session tokens, or page content. Any user of an iPhone, iPad, or Apple Watch running software older than iOS 12.5.2, iOS 14.4.2/iPadOS 14.4.2, or watchOS 7.3.3 is affected. Apple reported that the issue may have been actively exploited in the wild at the time of patching, it is on the CISA Known Exploited Vulnerabilities catalog (added 2021-11-03), and public reporting tied its use to targeted campaigns (including Russian SVR-linked operations), though no public proof-of-concept is known.

Do: Update devices to iOS 12.5.2 (older devices) or iOS 14.4.2/iPadOS 14.4.2, and Apple Watch devices to watchOS 7.3.3, per Apple's instructions. Because exploitation requires loading malicious web content in WebKit, avoid following untrusted web links on unpatched devices until updated; verify fleet-wide OS versions and confirm the fix, since this CVE is on the CISA KEV catalog with patching required. Check logs or browser history for signs of visits to attacker-controlled sites on devices that have since been updated, as no public proof-of-concept exists to test against.

6.17% KEV
  • Apple iOS (iPhone OS) versions prior to iOS 14.4.2; older devices on the iOS 12 branch prior to iOS 12.5.2
  • Apple iPadOS versions prior to iPadOS 14.4.2
  • Apple watchOS versions prior to watchOS 7.3.3
masshundreds of millions of devices (Apple's active iPhone/iPad/watchOS install base was on the order of 1+ billion when patched; all unpatched devices are exposed…
CVE-2023-41993
WebKit Code Execution Flaw in Apple iOS, iPadOS, macOS, and Safari

Apple's WebKit engine, which renders web content for Safari and for essentially all HTML processing on iOS, iPadOS, and macOS, contains a flaw that leads to code execution when processing maliciously crafted web content. It is triggered when a user's browser or embedded web view loads attacker-controlled web content, so simply visiting a hostile page can be enough. Successful exploitation could allow arbitrary code execution within the affected application's context, a common stepping stone to broader device compromise. All users of Apple iOS, iPadOS, macOS, and Safari are potentially affected, as are users of non-Apple products that rely on WebKit for HTML processing. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-25, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known.

Do: Apply Apple's latest security updates for iOS, iPadOS, macOS, and Safari that patch WebKit, following the vendor instructions referenced by the CISA KEV entry, and treat unpatched WebKit builds as actively exploited. Until systems are patched, restrict exposure to untrusted web content (e.g., limit browsing and in-app web views to trusted sites for high-risk users). Also inventory any non-Apple applications or HTML-processing components in your environment that bundle WebKit and update them as their maintainers ship fixes.

8.829% KEV
  • Apple iOS (WebKit)
  • Apple iPadOS (WebKit)
  • Apple macOS (WebKit)
  • +2 more
mass1+ billion devices/users (WebKit ships in Safari and all web-content rendering on iOS, iPadOS, and macOS)
CVE-2024-4671
Use-After-Free Sandbox Escape in Google Chrome/Chromium

CVE-2024-4671 is a use-after-free (CWE-416) in the Visuals component of Google Chrome and Chromium, fixed in Chrome 124.0.6367.201. It is triggered via a crafted HTML page, but the attacker must already have compromised the browser's renderer process, so this flaw is typically chained with a renderer exploit rather than used standalone. Successful exploitation enables a sandbox escape, letting the attacker break out of Chrome's renderer sandbox and gain broader access to the system beyond the browser tab. All users of Google Chrome versions prior to 124.0.6367.201 are affected, and per CISA's CPE data, Fedora's packaged Chromium builds are also in scope. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-05-13, indicating active exploitation in the wild; no public proof-of-concept is known, EPSS estimates an 8.3% chance of exploitation within 30 days (95th percentile), and ransomware association is unknown.

Do: Update Google Chrome to 124.0.6367.201 or later (verify via chrome://settings/help, since Chrome auto-updates may lag), and update Fedora's chromium package to the fixed build; CISA KEV requires federal agencies to apply the vendor fix on the mandated timeline. Because this sandbox escape must be chained with a renderer compromise, defenders should treat any unpatched Chrome deployment as exposed and confirm via EDR logs whether suspicious renderer-process activity occurred; enterprise admins should push the update through managed-browser channels immediately.

9.68% KEV
  • google chrome prior to 124.0.6367.201
  • fedoraproject fedora packaged Chromium builds prior to the 124.0.6367.201 fix
mass≈3+ billion Chrome/Chromium users worldwide (Chrome holds roughly 65% of desktop browser market share, with additional exposure via Chromium packaged in Fedora)
CVE-2024-5274
Google Chrome V8 Type Confusion Allows In-Sandbox RCE via Crafted HTML Pages

CVE-2024-5274 is a type confusion flaw (CWE-843) in the V8 JavaScript engine of Google Chrome prior to 125.0.6422.112. A remote attacker can trigger it by persuading a user to open or interact with a crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code inside the browser's sandbox, and the scope-changed CVSS scoring indicates potential impact beyond the browser process itself. Anyone running an affected Chrome or Chromium build, including Chromium-derived distributions such as Fedora's Chromium package, is exposed. The flaw was added to CISA's KEV on 2024-05-28, a public PoC reference exists, and related news reports describe it as actively exploited in the wild.

Do: Upgrade Google Chrome to 125.0.6422.112 or later and confirm the build via chrome://version; Fedora users and users of Chromium-derived browsers should install the corresponding updated packages from their vendor. Because the flaw is listed in CISA KEV, federal agencies and targeted organizations must apply the vendor fix or discontinue use per the required action, and all users should avoid untrusted web content until patched.

9.67% KEV PoC
  • Google Chrome (Chromium V8 engine) all versions prior to 125.0.6422.112
  • Fedora Project Fedora (Chromium browser package) versions shipping a vulnerable V8 engine; fixed version not specified in available data
masson the order of billions of users (Chrome has 3+ billion users and roughly two-thirds desktop browser share)

Indicators of compromiseAll →

TypeIndicatorContext
domaingov.mncovered a new watering hole attack targeting Mongolia’s mfa.gov[.]mn website where they inserted code used to deliver a Google
Full article807 words · extracted from therecord.media · click to collapse

Google security researchers said they uncovered an espionage campaign against websites run by the Mongolian government, attributing the operation to Russia-backed hackers using exploits previously deployed by commercial surveillance vendors Intellexa and NSO Group.

A Google spokesperson told Recorded Future News that the campaign stood out because it was the first time the researchers saw alleged members of the Russian group tracked as APT29 using the same exploits as those sold by commercial surveillance vendors. 

“We do not know how they were acquired and if Intellexa or NSO knowingly sold them to the Russian government,” they added.

The campaign used the websites as “watering holes” — a type of attack that targets specific groups of people by compromising popular platforms they are likely to visit. In a report posted Thursday, Google’s Threat Analysis Group (TAG) said the operation ran between November 2023 and July 2024. 

APT29 added malicious code to the website for Mongolia’s Ministry of Foreign Affairs and the website for the country’s cabinet, Google said. 

The campaigns first delivered exploits targeting iPhone users and then added versions to target Android and Chrome users, the researchers said. Patches have been released for all of the exploits but the campaign would have been successful against those who have not patched their devices. 

The Apple vulnerability — CVE-2023-41993 — affects iPhone users running versions 16.6.1 or older, and TAG found tactical evidence tying it to a previously observed campaign run by APT29. The Google bugs targeted were CVE-2024-5274 and CVE-2024-4671. 

TAG said it notified Mongolia’s cybersecurity bureau and Apple as well as Android and Google Chrome about the campaign. 

The goal of the campaign was to exfiltrate browser cookies from a device. TAG explained that the Apple exploit “used the exact same trigger” as an exploit used by Intellexa, “strongly suggesting the authors and/or providers are the same.”

Intellexa was blacklisted by the U.S. government last year for its role in manufacturing spyware. 

TAG shared images that showed both the exploit used in the watering hole attack and the exploit deployed by Intellexa in September 2023 had the same code. 

“The iOS exploit loaded the same cookie stealer framework that TAG observed in March 2021 when a Russian government-backed attacker exploited CVE-2021-1879 to acquire authentication cookies from prominent websites such as LinkedIn, Gmail, and Facebook,” TAG explained. “In that campaign, attackers used LinkedIn Messaging to target government officials from western European countries by sending them malicious links.”

NSO Group tools

The attacks on Apple and Android devices used various tools to identify which hardware was attempting to access the websites before initiating the attacks. 

The Android-focused operation used CVE-2024-5274, which was discovered by TAG in May after it was used by NSO Group. NSO Group is one of the most prominent spyware companies in the world, facing immense backlash after its tools were discovered in a campaign against dozens of world leaders, journalists, human rights workers and more

The exploit used by NSO Group was adapted and changed by APT29 in ways that went beyond how the attackers did with the Intellexa exploit for Apple devices. 

TAG said at the end of July, they discovered a new watering hole attack targeting Mongolia’s mfa.gov[.]mn website where they inserted code used to deliver a Google Chrome exploit chain to Android users.

“From a high level overview, the attack and end goal are essentially the same as the iOS one – using n-day vulnerabilities in order to steal credential cookies – with some differences on the technical side,” TAG said. 

The goal for the Chrome-focused campaign was to steal saved cookies for all websites, as well as account data like credit cards, passwords stored in Chrome, a user’s Chrome history and more. 

While the researchers do not know how the exploits were obtained by APT29, they warned that similar advanced persistent threat (APT) groups are now using exploits that were originally used by commercial vendors. 

Watering hole attacks “remain a threat where sophisticated exploits can be utilized to target those that visit sites regularly, including on mobile devices,” TAG said. 

APT29 — associated with Russia’s foreign intelligence service, the SVR — is one of the Kremlin’s highest-profile hacking operations. The group, also known as Cozy Bear, recently drew headlines for an attack on popular remote access software company TeamViewer.

Recorded Future News reported three weeks ago that APT29 was also responsible for accessing emails and data from officials working within the British government through an attack on Microsoft earlier this year

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/mongolia-apt29-watering-hole-attacks-exploits-nso-group-intellexa