pwshub.com

Google reports watering-hole attacks on Mongolian sites leveraged iOS and Android exploits

Google LLC’s Threat Analysis Group today shared details on multiple observed in-the-wild exploit campaigns that used watering-hole attacks on Mongolian government websites between November 2023 and July this year.

A watering-hole attack is a strategy that involves attackers compromising legitimate websites that their target or targets frequently visit by embedding malicious code to exploit vulnerabilities in the target’s devices. The goal is to infect visitors with malware or steal sensitive information when they access the compromised site.

In the case of the campaign targeting Mongolian government websites, those behind the attack targeted mobile users on both Apple Inc. and Android devices. Those behind the campaign at first delivered an iOS WebKit exploit affecting iOS versions older than 16.6.1 and then, later, a Chrome exploit chain against Android users running versions from m121 to m123.

The campaigns delivered n-day exploits for which patches were available but would still be effective against unpatched devices.

The iOS exploit was delivered by the attackers by exploiting the websites to serve an iframe that delivered malicious code to exploit unpatched Apple phones. The payload included a cookie stealer framework that had previously been seen in 2021 targeting European officials and also included a reconnaissance payload to identify vulnerable devices before deploying the exploit.

The campaign targeting Android, which also involved the compromise of Mongolian government websites, used obfuscated JavaScript to inject the malicious iframe, leveraging a previously known NSO Group exploit method. The final payload collected sensitive user data, including cookies, account information and browsing history.

Both campaigns are said to have reused or closely mirrored previously observed exploits from commercial surveillance vendors like Intellexa and NSO Group Ltd. However, there were some notable differences between the attackers’ methods and objectives, such as cookie theft and data exfiltration, that are more aligned with state-sponsored activities. “We assess with moderate confidence the campaigns are linked to the Russian government-backed actor APT29,” the Google researchers wrote.

APT29, also known as Cozy Bear, has previously been linked to or credited with attacks on TeamViewer SE in June and an attack on the U.S. Treasury and Commerce Departments in December 2020.

“Watering hole attacks remain a threat where sophisticated exploits can be utilized to target those that visit sites regularly, including on mobile devices,” Google’s researchers conclude. “Watering holes can still be an effective avenue for n-day exploits by mass targeting a population that might still run unpatched browsers.”

Source: siliconangle.com

Related stories
2 weeks ago - All eyes were on Nvidia’s earnings report this week as a proxy for the artificial intelligence economy, and even for the graphics chip giant, it was too much to live up to. Nvidia earnings disappointed, but really, how could they not?...
1 week ago - YouTube has deleted the channel of Tenet Media, a right-wing content production company that recent media reports have linked to a Russian influence operation. A spokesperson for the Google LLC unit told The Washington Post today that the...
1 month ago - Google LLC and the state of California have agreed to a deal under which the tech giant will commit $172.5 million to fund local journalism over the next five years while some of the money will be set aside for artificial intelligence...
1 month ago - Google (GOOG, GOOGL) suffered a staggering shot to its search and advertising business on Monday as District of Columbia's Judge Amit Mehta ruled in...
1 month ago - A judge has ruled that Google violated antitrust law by abusing its dominance in online search, a major blow for the tech giant and a huge win for Justice Department.
Other stories
1 hour ago - (Bloomberg) -- Skechers U.S.A. Inc. shares delivered their worst daily performance since February after the footwear company’s chief financial officer told an industry conference that China sales will be under pressure the rest of the...
2 hours ago - The Fed's cutting cycle in 1995 sparked an economic boom, with the stock market more than doubling in value by the end of the decade.
2 hours ago - There's nothing like a potentially massive government contract to win the hearts of both investors and analysts.
3 hours ago - Shares of Truth Social’s parent company fell Thursday, extending the latest round of declines for Trump Media & Technology Group.
4 hours ago - European Union officials are taking new steps to ensure that Apple Inc. complies with the bloc’s DMA tech industry regulation. The European Commission, the EU’s executive arm, announced the initiative today. The DMA is a piece of...