Israel-based spyware vendor Candiru (also known as Saito Tech) was found to be using a zero-day vulnerability in Google Chrome to spy on journalists and other high-profile individuals in the Middle East with the “DevilsTongue ” spyware. The company offers spyware services to governments.

Candiru, like NSO Group, claims its software is designed to be used by governments and law enforcement agencies to prevent potential terrorism and crime, but researchers have found that authoritarian regimes have used the spyware to target journalists, political dissidents, and critics of repressive regimes. Candiru has been sanctioned by the U.S. Department of Commerce for engaging in activities contrary to U.S. national security.
See also: Windows 11: KB5015882 update fixes bugs causing problems in File Explorer
The zero-day flaw exploited by the “DevilsTongue” spyware, tracked as CVE-2022-2294 , is a high-severity heap-based buffer overflow flaw in WebRTC. Successful exploitation could lead to code execution on the target device.
Google patched the zero-day vulnerability on July 4 and revealed at the time that the vulnerability was already being used in attacks. However, the company did not provide further details about those attacks.
The vulnerability was discovered and reported to Google by researchers at Avast. According to the researchers' report, the vulnerability was discovered after investigating spyware attacks on their customers.
According to Avast, Candiru began exploiting the zero-day vulnerability CVE-2022-2294 in March 2022, targeting users in Lebanon, Turkey, Yemen, and Palestine.
The spyware operators used common attack tactics, hacking into a website that their targets are visiting and exploiting an unknown vulnerability in the browser. The end goal is to infect them with spyware. This attack is particularly dangerous because it does not require any interaction with the victim, such as clicking on a link or downloading a file. Instead, all that is required is opening a site in Google Chrome or another Chromium-based browser.
These sites can either be legitimate that were compromised in some way or malicious that were created directly by the attackers and promoted through spear phishing or other methods.
According to the researchers' report, in one case, attackers compromised a website used by a news agency in Lebanon and placed JavaScript snippets that enabled attacks XXS (cross-site scripting) and directed valid targets to the exploit server.
See also: Windows 11 blocks RDP brute-force attacks by default
Once victims reach the server, profiles are created with many details.
“The information collected includes the victim’s language, time zone, screen information, device type, browser plugins, referrer, device memory, cookie functionality, and more,” Avast’s report explains.
In the case of Lebanon, the zero-day allowed attackers to achieve shellcode execution within a renderer process and was combined with a sandbox escape flaw that Avast was unable to recover for analysis.
Because the flaw was found in WebRTC, it also affected Apple 's Safari browser . However, the exploit Avast saw only worked on Windows.

After initial infection, Candiru's DevilsTongue spyware used a BYOVD (“bring your own driver”) step to escalate its privileges and gain read and write access to the compromised device's memory.
While it's unclear what data the attackers were targeting, Avast believes the threat actors used it to learn more about the news the targeted journalist was researching.
“We can’t say for sure what the attackers might be looking for, however, often the reason attackers target journalists is to spy on them for the stories they are working on or to reach their sources and collect sensitive data that they shared with the press.” – Avast.
See also: Neopets: Breach exposes personal information of 69 million members
Candiru spyware: Continuing spyware
Spyware vendors are known to purchase or create zero-day exploits to attack people of interest to their customers.
The last time Candiru was exposed by Microsoft and Citizen Lab, it removed all DevilsTongue functionality and secretly worked to implement new zero-days, as Avast now reveals.

This means that security updates are not enough, as spyware vendors are constantly finding new ways to attack.
Apple is trying to address the spyware threat by bringing a new iOS 16 feature called “Lockdown Mode,” which will provide customers with protection related to messaging, web browsing, and general connectivity, so they are not at risk from spyware (like Pegasus ) that may be used by government-backed hackers.
Source: www.bleepingcomputer.com
