HomeSecurityHackers used 11 zerodays to infect Windows, iOS and Android

Hackers used 11 zero-days to infect Windows, iOS and Android

In an operation that lasted about 9 months, a group of experienced hackers exploited 11 zero-days to infect fully updated devices running Windows, iOS and Android, a Google.

Zero-day hackers

See also: Apple will likely offer iOS security updates independently of others

Using innovative exploitation techniques and knowledge of a wide range of vulnerability types, the group exploited four zero-days in February 2020. As it turned out, the group had the ability to combine multiple exploits, which compromised even fully updated Windows and Android devices. Because of this, Google’s Project Zero and Threat Analysis team described the hackers as “highly sophisticated.”

On Thursday, Project Zero researcher Maddie Stone said that in the eight months since the February attacks, the same group has exploited seven more previously unknown vulnerabilities, this time on iOS devices. As in February, the hackers distributed the exploits through watering-hole attacks, which compromise websites targeting targets of interest and add code that installs malware on visitors’ devices.

In all attacks, the watering-hole sites redirected visitors through an infrastructure designed to install different exploits depending on the devices and browsers the visitors were using. While the two servers used in February only exploited Windows and Android devices, subsequent attacks also exploited iOS devices.

Zero-day hackers

See also: How Android apps will not use mobile data in the background

The ability to bypass advanced defenses built into well-updated operating systems and applications is a testament to the team's prowess. Another testament to this was the team's abundance of zero-days. After Google patched a code execution vulnerability that attackers had exploited in the Chrome renderer in February, hackers promptly added a new code execution exploit for the Chrome V8 engine.

See also: Google Chrome for desktop will receive a major improvement

Thursday's post did not provide details about the group responsible for the attacks. It would be particularly interesting to know whether the hackers belong to a group already known to researchers or if it is a group that has not appeared before. Information about the individuals targeted would also be useful.

The importance of keeping applications and operating systems updated and avoiding suspicious websites remains high. Unfortunately, none of these measures helped the victims affected by this unknown group.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS