ZeroHour
Security Affairspublished ()ingested @securityaffairs

Facebook vs NSO Group lawsuit: 1,400+ users were targeted with Pegasus spyware

mediumMalwareimportance 35CVE-2019-3568

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-3568
Buffer Overflow RCE in WhatsApp VoIP Stack via Crafted RTCP Packets

A buffer overflow (CWE-122) in the VoIP telephony stack of WhatsApp allowed a remote attacker to achieve remote code execution on a target device by sending a specially crafted series of RTCP packets to the victim's phone number. Because the flaw resided in the call-handling stack of the core app, an attacker who could reach the target's phone number over the network could gain arbitrary code execution on the device. All WhatsApp users at the time of disclosure were potentially exposed, since the vulnerable component shipped in the mainstream Meta Platforms (then Facebook) product rather than an optional add-on. The vulnerability was added to CISA's Known Exploited Vulnerability catalog on 2022-04-19, indicating confirmed real-world exploitation, and its EPSS score of 39.2% (99th percentile) signals a high likelihood of continued exploitation; no public proof-of-concept is known. It was remediated in vendor updates issued in 2019 and is widely associated with targeted espionage use (notably Pegasus spyware deployments).

Do: Update WhatsApp on all mobile devices to the latest vendor release, per the CISA KEV required action; inventory your mobile fleet for outdated 2019-era builds and verify current app versions. Prioritize high-value targets (executives, journalists, government personnel) given the vulnerability's confirmed in-the-wild exploitation in espionage campaigns. No public PoC is known, but the flaw is remotely exploitable via network packets to a phone number, so treat patching as urgent.

9.830% KEV
  • Meta Platforms WhatsApp
mass≈1.5–2 billion users (effectively the entire global WhatsApp user base at the time of disclosure)

Indicators of compromiseAll →

TypeIndicatorContext
ipv4104.223.76.220instances of the attack, the remote server’s IP address was 104.223.76.220 . In 3 instances of the attack, the remote server’s IP addr
ipv454.93.81.200instances of the attack, the remote server’s IP address was 54.93.81.200 ,” In April, attorneys for the NSO Group filed a motion to
Full article411 words · extracted from securityaffairs.com · click to collapse

The legal dispute between Facebook and NSO group continues even after the Israeli surveillance firm filed a motion to dismiss the case earlier this month.

Facebook advocates have challenged a plea from spyware maker NSO Group to dismiss the legal dispute over the hacking accusations, arguing it has immunity from prosecution.

Now both companies are providing technical details requested by the cyber-security experts. according to court documents shared by ZdNet, Facebook linked at least 720 attacks against WhatsApp users to one single IP address.

The surveillance implant used by the NSO group used an exploit for a vulnerability, tracked as CVE-2019-3568, in the WhatsApp VoIP feature.

The attacks took place in the spring of 2019, Facebook states that more than 1,400 users were targeted with the NSO Pegasus spyware, including, journalists, human rights activists, political dissidents, diplomats, attorneys, and government officials.

“I have reviewed the malicious code sent during the attack described in the Complaint. That malicious code was designed to cause a WhatsApp user’s mobile device to connect to a remote server not associated with WhatsApp. The IP address of the remote server was included in the malicious code,” explained Claudiu Gheorghe, a software engineering for WhatsApp.

“In 720 instances of the attack, the remote server’s IP address was 104.223.76.220. In 3 instances of the attack, the remote server’s IP address was 54.93.81.200,”

In April, attorneys for the NSO Group filed a motion to dismiss the hacking case, among the observations raised by the advocates there was the lack of jurisdiction of a California court to preside over the case, but investigators pointed out that the IP address 104.223.76.220 belongs to QuadraNet Enterprises LLC, a data center provider in Los Angeles.

Facebook attorneys also remarked that the NSO group is also financed by a California private equity firm.

“To execute its scheme and install its spyware on WhatsApp users’ devices, NSO separately entered into a contract with a California-based technology company, QuadraNet, that included a California choice-of-law clause,” Facebook said.

The NSO attorneys always remarked that the surveillance firm should be immune to prosecution because it was contracted by a foreign government, but the Facebook legal team refused this justification, there is no immunity granted to organizations involved in surveillance activities committed by foreign states.

Please give me your vote for European Cybersecurity Blogger Awards – VOTE FOR YOUR WINNERS
https://docs.google.com/forms/d/e/1FAIpQLSe8AkYMfAAwJ4JZzYRm8GfsJCDON8q83C9_wu5u10sNAt_CcA/viewform

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Facebook, NSO Group)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/102260/laws-and-regulations/facebook-nso-group-lawsuit.html