HomeSecurityRussian hackers use exploits created by NSO Group and Intellexa

Russian hackers use exploits created by NSO Group and Intellexa

Russian hackers APT29 use iOS and Android exploits (the same or very similar) created by spyware vendors such as NSO Group and Intellexa in their attacks

Russian hackers APT29

The attacks were discovered by Google's Threat Analysis Team (TAG) and took place from November 2023 to July 2024. Researchers said the vulnerabilities used have been patched, but devices that have not received the relevant updates remain vulnerable.

Russian hackers APT29 have targeted multiple Mongolian government websites and used “watering hole” tactics. During a watering hole attack, a legitimate website is compromised with malicious code that distributes payloads to visitors, taking into account some criteria, such as device architecture or location (based on IP).

See also: Android spyware Mandrake hides in apps on Google Play

However, Google researchers noticed that in these attacks, Russian hackers APT29 used exploits that were almost identical to those created by spyware vendors NSO Group and Intellexa . These companies create exploits for unpatched zero-day vulnerabilities and use them to compromise systems with their software

APT29: Attacks

Google analysts explained that the APT29 group often exploits zero-day and n-day vulnerabilities to carry out attacks. For example, in 2021, Russian hackers exploited the zero-day vulnerability CVE-2021-1879to target government officials in Eastern Europe. In November 2023, they compromised the Mongolian government websites “mfa.gov.mn” and “cabinet.gov.,mn” using CVE-2023-41993 (a WebKit bug to steal browser cookies from iOS users).

Google researchers say this latest exploit was exactly the same as the one used by Intellexa in September 2023, leveraging CVE-2023-41993 as a vulnerability .

In February 2024, Russian hackers APT29 compromised another Mongolian government website, “mga.gov.mn,” with the same exploit.

See also: Apple warns iPhone users in 98 countries about spyware attacks

Finally, in July, the group used exploits for CVE-2024-5274 and CVE-2024-4671 to attack Android visiting "mga.gov.mn" and "adv.com."

NSO Group Intellexa spyware

The Russian hackers' goal was to steal cookies, passwords, and other sensitive data stored in the victims' Chrome browser.

The exploit used for CVE-2024-5274 is slightly different from the one used by NSO Group in May 2024, while the exploit for CVE-2024-4671 had many similarities to previous Intellexa exploits.

How is APT29 connected to spyware vendors?

At this time, it is not certain how APT29 gained access to the exploit information. Perhaps the Russian hackers managed to breach the spyware vendors and steal useful data. Or perhaps they bribed company employees to give them the information. There could also be some collaboration between the hackers and the companies.

Whatever happened, the result is the same: state hackers are using the exploits and carrying out attacks. This makes it even more critical to address zero-day vulnerabilities early.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Hackers infect Hamster Kombat users with spyware

Russian hackers use exploits created by NSO Group and Intellexa
Russian hackers use exploits created by NSO Group and Intellexa

These vulnerabilities can have serious consequences for both individuals and organizations:

Data Breaches: Hackers can exploit zero-day vulnerabilities to gain unauthorized access to sensitive data, resulting in data breaches and potential financial loss.

Security breaches: Zero-day bugs can also be used by attackers to gain unauthorized access to systems and networks, compromising the security of an organization's infrastructure.

Financial Loss: In addition to direct losses from data or security breaches , zero-day bugs can also lead to financial loss due to business downtime, reputational damage, and legal liabilities.

It is important for developers to prioritize security and for individuals and organizations to take proactive steps to mitigate the impact of these dangerous vulnerabilities. Regular updates, cybersecurity education and awareness, and implementation of basic security are essential steps to protect against zero-day bugs.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS