loader image

Wed, Sep 18 | 9:55 pm

Russian Hackers Exploit Spyware Codes from NSO Group and Intellexa, Says Google

by | Aug 31, 2024

Google has uncovered evidence that Russian government hackers, identified as APT29, are using spyware exploits originally developed by NSO Group and Intellexa. These exploits, which had previously been patched, were found embedded on Mongolian government websites in a watering hole attack targeting iPhones and Android devices between November 2023 and July 2024.

APT29, also known as Cozy Bear, is a notorious hacking group linked to Russia’s Foreign Intelligence Service (SVR). The group is known for its sophisticated cyber-espionage campaigns aimed at major tech companies, foreign governments, and critical infrastructure. Google’s Threat Analysis Group (TAG) revealed that APT29 used these exploits to steal user data, including passwords and account cookies, through vulnerabilities in the Safari browser on iPhones and Google Chrome on Android devices.

The attack involved hidden exploit code on websites frequented by Mongolian government employees. The stolen cookies from these visits could then be used to access personal and work accounts. Google highlighted that although the vulnerabilities had been patched, the exploits remained effective on devices that had not been updated.

A key concern raised by Google is how the Russian hackers obtained the exploits. The security firm noted that the exploits used by APT29 were either “identical or strikingly similar” to those developed by NSO Group and Intellexa. The reuse of these codes suggests that Russian hackers may have acquired the exploits through purchase or theft. Google ruled out the possibility that the exploits were independently recreated, given the complexity and specificity of the code.

Google emphasized the importance of keeping software up-to-date to prevent such attacks, particularly on high-risk devices. iPhone and iPad users with the Lockdown Mode feature enabled were not affected by the attack, even if they were running vulnerable software versions. This incident underscores the ongoing global risks associated with spyware technology and its potential misuse by state actors.

0 Comments

text

 

 

 

 

 

 

text

 

 

 

 

 

 

Related Posts

Severe Drought in Brazil’s Amazon Disrupts Lives and Economy

Severe Drought in Brazil’s Amazon Disrupts Lives and Economy

A severe drought across Brazil's Amazon rainforest is drastically affecting the lives of residents, especially in towns like Manacapuru, near the state capital of Manaus. Record-low water levels in the upper stretches of the Amazon River, including its tributary the...

New US Shipping Rules Target Shein and Temu Amid Growing Scrutiny

New US Shipping Rules Target Shein and Temu Amid Growing Scrutiny

The Biden administration has proposed new regulations aimed at imposing taxes on low-value shipments from China, particularly those from popular e-commerce platforms Shein and Temu. These rules would eliminate an existing exemption that allows packages worth less than...

Eight Dead After Tragic Channel Crossing Attempt

Eight Dead After Tragic Channel Crossing Attempt

Eight people tragically lost their lives overnight while attempting to cross the English Channel from France to England, French authorities reported. The incident occurred in the early hours of Sunday when a rubber boat, carrying around 60 migrants from countries...