ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google TAG argues that Italian surveillance firm RCS Labs was helped by ISPs to infect mobile users

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-4344
Memory Corruption Flaw in Apple iOS, macOS, tvOS, and watchOS (Pre-2018 Releases)

CVE-2018-4344 is a memory corruption vulnerability (CWE-119) in Apple's operating systems that was fixed with improved memory handling in the Fall 2018 releases. It carries a local attack vector with user interaction required (CVSS AV:L/UI:R), meaning exploitation requires the victim to process attacker-supplied content, and successful exploitation yields high confidentiality, integrity, and availability impact, consistent with potential arbitrary code execution. Every user running versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 is affected, spanning iPhone/iPad, Mac, Apple TV, and Apple Watch. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2022-06-27, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use is listed as unknown. EPSS currently estimates a 2.9% probability of exploitation within 30 days (86th percentile).

Do: Upgrade affected devices to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 or later per Apple's instructions, as required by the CISA KEV listing. Inventory your fleet for Apple devices running outdated OS versions; for hardware that cannot run iOS 12, treat the device as permanently unpatched and replace or isolate it. Because the flaw is confirmed exploited in the wild and appears in KEV, prioritize these updates in patch cycles, particularly on user workstations and BYOD endpoints.

7.83% KEV
  • apple iPhone OS (iOS) on iPhone and iPad All versions prior to iOS 12
  • apple macOS (mac OS X) All versions prior to macOS Mojave 10.14
  • apple tvOS on Apple TV All versions prior to tvOS 12
  • +1 more
masshundreds of millions of Apple devices ran iOS/macOS/tvOS/watchOS versions below the 2018 fixes at disclosure, with an unknown but likely substantial share…
CVE-2019-8605
Use-After-Free in Apple iOS, macOS, tvOS, watchOS Enables Privileged Code Execution

CVE-2019-8605 is a use-after-free memory corruption flaw (CWE-416) affecting Apple's iOS, macOS (Mojave), tvOS, and watchOS, addressed with improved memory management in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1. It is triggered locally: a malicious application running on a device (the CVSS vector requires user interaction, meaning the victim must run the malicious app) exploits the stale-memory condition. A successful attack allows the application to execute arbitrary code with system privileges, i.e., a privilege escalation or sandbox escape beyond normal app permissions. Any iPhone, iPad, Mac, Apple TV, or Apple Watch running an OS version older than the fixed releases is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), indicating known in-the-wild exploitation, with a high EPSS score of ~17.5% (97th percentile) and no known public proof-of-concept.

Do: Update iPhones/iPads to iOS 12.3 or later, Macs to macOS Mojave 10.14.5 or later, Apple TVs to tvOS 12.3 or later, and Apple Watches to watchOS 5.2.1 or later. Use MDM or endpoint inventory to identify devices still running older OS versions, prioritizing KEV-driven patching requirements. Until patched, limit exposure by installing applications only from trusted sources, since exploitation requires running a malicious local application.

7.818% KEV
  • apple iphone os (iOS) versions prior to iOS 12.3 (fixed in iOS 12.3)
  • apple mac os x (macOS Mojave) versions prior to macOS Mojave 10.14.5 (fixed in 10.14.5)
  • apple tvos versions prior to tvOS 12.3 (fixed in tvOS 12.3)
  • +1 more
masshundreds of millions of Apple devices ran affected OS versions at disclosure; devices remaining on pre-fix versions today are likely in the millions (exact…
CVE-2020-3837
Memory Corruption in Apple iOS, macOS, tvOS, watchOS Enables Kernel-Level Code Execution

Apple patched an out-of-bounds write (CWE-787), a memory corruption flaw in kernel memory handling, across iOS/iPadOS, macOS Catalina, tvOS and watchOS. The flaw is triggered by a local application performing the faulty memory access, and the CVSS vector indicates user interaction (running the application) is required. A successful attacker can execute arbitrary code with kernel privileges, meaning full compromise of the affected device. Anyone running iPhone/iPad, Mac, Apple TV or Apple Watch software older than iOS/iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1 and watchOS 6.1.2 respectively is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), so exploitation has been observed in the wild, and EPSS assigns a 16.1% probability of exploitation within 30 days (97th percentile).

Do: Update all Apple endpoints to the fixed releases: iOS and iPadOS 13.3.1 or later, macOS Catalina 10.15.3 or later, tvOS 13.3.1 or later, and watchOS 6.1.2 or later; apply per vendor instructions to satisfy the KEV required action. Inventory managed and BYOD Apple devices for OS versions below these builds and prioritize patching, since the flaw is KEV-listed and mobile spyware campaigns targeting iPhones are active (e.g., LightSpy, though no confirmed link to this CVE is in the data). Until devices are patched, limit installing applications from untrusted sources, as triggering requires running a local application.

7.816% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 13.3.1
  • Apple iPadOS versions prior to iPadOS 13.3.1
  • Apple macOS (Catalina) versions prior to macOS Catalina 10.15.3
  • +2 more
masswell over 1 billion active Apple devices in the affected installed base (iPhone/iPad/Mac/Apple TV/Apple Watch)
CVE-2020-9907
Memory Corruption with Kernel Privileges in Apple iOS, iPadOS, and tvOS

Apple patched a kernel memory corruption flaw (CWE-787, out-of-bounds write) in iOS 13.6, iPadOS 13.6, and tvOS 13.4.8 by removing the vulnerable code. The flaw is triggered locally: an application running on the device (local attack vector, user interaction required per the CVSS scoring) can corrupt kernel memory and execute arbitrary code with kernel privileges. A successful attacker gains the highest privilege level on the device, effectively escalating from an application to full kernel control. Anyone running an iPhone, iPad, or Apple TV on versions earlier than iOS/iPadOS 13.6 or tvOS 13.4.8 is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-06-27, indicating exploitation in the wild, though no public proof-of-concept is known and EPSS estimates a roughly 3.9% chance of exploitation in the next 30 days.

Do: Upgrade iPhones and iPads to iOS/iPadOS 13.6 or later and Apple TV devices to tvOS 13.4.8 or later, per CISA's required action to apply vendor updates. Because the KEV listing confirms in-the-wild exploitation, prioritize patching and check current builds via Settings > General > Software Update. On unpatched devices, limit exposure by only installing trusted applications, since triggering the flaw requires an application running locally on the device.

7.84% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 13.6
  • Apple iPadOS versions prior to iPadOS 13.6
  • Apple tvOS versions prior to tvOS 13.4.8
masshundreds of millions of Apple devices at the time of disclosure (subset of the iOS/iPadOS installed base on pre-13.6 builds, plus legacy Apple TV units)
CVE-2021-30883
Kernel Memory Corruption Zero-Day in Apple iOS, iPadOS, macOS, tvOS, watchOS

CVE-2021-30883 is a memory corruption flaw (CWE-787, out-of-bounds write) in the kernel of Apple's iOS, iPadOS, macOS, tvOS, and watchOS, addressed with improved memory handling. It is triggered by a local application that mishandles memory, with the CVSS vector (AV:L, UI:R) indicating a user must run or interact with the malicious app. Successful exploitation allows arbitrary code execution with kernel privileges, giving an attacker full control over the affected device. All users of iPhones, iPads, Macs, Apple TVs, and Apple Watches running versions earlier than the patched releases are affected. Apple acknowledged the issue may have been actively exploited in the wild, and CISA added it to the KEV catalog; related reporting indicates it was among 2021 zero-days developed commercially and sold to government clients.

Do: Upgrade iPhones and iPads to iOS/iPadOS 15.0.2 (or 14.8.1 for devices staying on iOS 14), Macs to macOS Monterey 12.0.1 or Big Sur 11.6.1, Apple TVs to tvOS 15.1, and Apple Watches to watchOS 8.1. As a CISA KEV entry, the required action is to apply updates per vendor instructions; inventory managed Apple devices and verify OS versions to confirm patching, prioritizing high-risk users who may have been targeted by commercial spyware.

7.815% KEV
  • Apple iPhone OS (iOS) prior to iOS 15.0.2 (iOS 15 line) and prior to iOS 14.8.1 (iOS 14 line)
  • Apple iPadOS prior to iPadOS 15.0.2 and prior to iPadOS 14.8.1
  • Apple macOS prior to macOS Monterey 12.0.1 and prior to macOS Big Sur 11.6.1
  • +2 more
mass≈1 billion+ Apple devices (iPhone/iPad/Mac/Apple TV/Apple Watch installed base running the affected OS versions)
CVE-2021-30983
Kernel Buffer Overflow in Apple iOS and iPadOS Enables Arbitrary Code Execution

CVE-2021-30983 is a buffer overflow (CWE-120) in Apple iOS and iPadOS, caused by improper memory handling, that was corrected in iOS 15.2 and iPadOS 15.2. It is triggered locally by an application running on the device (CVSS local attack vector with user interaction), so a user must run a malicious or compromised app for the flaw to be reached. Successful exploitation allows that application to execute arbitrary code with kernel privileges, giving the attacker near-complete control of the affected iPhone or iPad. Anyone using an iPhone or iPad running a version earlier than iOS/iPadOS 15.2 is affected. The vulnerability is confirmed exploited in the wild, having been added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-27, with EPSS estimating a 2.9% probability of exploitation within 30 days; no public proof-of-concept is known.

Do: Upgrade all iPhones and iPads to iOS 15.2 or iPadOS 15.2 or later per Apple's instructions, as this is the required action in CISA's KEV catalog. Use MDM or device inventory to identify any devices still below 15.2 and prioritize them for patching; until updated, limit app installation from untrusted sources, since exploitation requires running an application on the device.

7.83% KEV
  • Apple iOS (iPhone OS) All versions prior to iOS 15.2
  • Apple iPadOS All versions prior to iPadOS 15.2
masshundreds of millions of iPhone/iPad devices (Apple's active installed base exceeds 1 billion; every device not yet updated to iOS/iPadOS 15.2 is affected)
Full article609 words · extracted from securityaffairs.com · click to collapse

Google’s Threat Analysis Group (TAG) revealed that the Italian spyware vendor RCS Labs was supported by ISPs to spy on users.

Researchers from Google’s Threat Analysis Group (TAG) revealed that the Italian surveillance firm RCS Labs was helped by some Internet service providers (ISPs) in Italy and Kazakhstan to infect Android and iOS users with their spyware.

Google experts have been tracking the activities of surveillance firms for years, its experts reported that seven of the nine zero-days discovered by TAG in 2021 were developed by commercial providers and sold to and used by government-backed actors. TAG researchers tracked more than 30 vendors selling exploits or surveillance capabilities to nation-state actors.

The attack chain implemented by RCS Labs for all the campaigns uncovered by TAG began with a unique link sent to the target. Once clicked the link, the victim is redirected to a page designed to trick users into downloading and installing a malicious application on either Android or iOS.

“In some cases, we believe the actors worked with the target’s ISP to disable the target’s mobile data connectivity. Once disabled, the attacker would send a malicious link via SMS asking the target to install an application to recover their data connectivity.” reads the report published by Google. “We believe this is the reason why most of the applications masqueraded as mobile carrier applications. When ISP involvement is not possible, applications are masqueraded as messaging applications.”

In case the threat actors cannot receive the help of the ISP, they used applications masqueraded as messaging applications.

The following image shows a landing page to trick Italian users into installing one of the following apps in order to recover their accounts. The analysis of the code of the page shows that only the WhatsApp download links are pointing to attacker-controlled content for Android and iOS users.

Google TAG researchers observed the Italian firm sideloading the iOS version, which was signed with an enterprise certificate. Then the attackers asked the victims to enable the installation of apps from unknown sources.

The iOS app analyzed by the researchers contained the following exploits:

  • CVE-2018-4344 internally referred to and publicly known as LightSpeed.
  • CVE-2019-8605 internally referred to as SockPort2 and publicly known as SockPuppet
  • CVE-2020-3837 internally referred to and publicly known as TimeWaste.
  • CVE-2020-9907 internally referred to as AveCesare.
  • CVE-2021-30883 internally referred to as Clicked2, marked as being exploited in-the-wild by Apple in October 2021.
  • CVE-2021-30983 internally referred to as Clicked3, fixed by Apple in December 2021.

“All exploits used before 2021 are based on public exploits written by different jailbreaking communities. At the time of discovery, we believe CVE-2021-30883 and CVE-2021-30983 were two 0-day exploits. In collaboration with TAG, Project Zero has published the technical analysis of CVE-2021-30983.” continues the analysis.

In the Android infections, threat actors did not use exploits, they tricked victims into granting permissions to install applications from unknown sources.

To protect Android users, Google warned them and implemented changes in Google Play Protect and disabled Firebase projects that were used as C2 in this campaign.

This week, Lookout Threat Lab researchers uncovered enterprise-grade Android surveillance spyware, named Hermit, used by the government of Kazakhstan to track individuals within the country.

According to Lookout, the Hermit spyware was likely developed by Italian surveillance vendor RCS Labs S.p.A and Tykelab Srl, the latter is a telecommunications solutions company suspected to be operating as a front company.

Google already notified Android users infected with the Hermit spyware and implemented changes in Google Play Protect to protect all users.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, RCS Labs)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/132553/malware/rcs-labs-spyware-spreads.html