Google's Threat Analysis Group breaks down three recent malware campaigns, likely state-backed, and notes a large uptick of in-the-wild 0-day attacks this year
Zero-day vulnerabilities are unknown software flaws. Until they're identified and fixed, they can be exploited by attackers.
The KeywordMaddie Stone
Context & Ripple Effects
Google’s warning followed a TAG-discovered actively exploited Chrome flaw in 2020, extending the group’s public reporting from individual browser vulnerabilities to campaign-level activity assessed as likely state-backed.
The alert also foreshadowed a sustained rise in detected exploitation: Project Zero later recorded 58 in-the-wild zero days in 2021, while subsequent Google research identified espionage actors as a major source of abuse.
First-order effects
Google’s Threat Analysis Group publicly identifies three malware campaigns as likely state-backed, giving defenders concrete campaign activity to prioritize alongside vulnerability patching.
The reported uptick elevates in-the-wild zero days from isolated software defects to an active threat-intelligence concern for Google’s security operations.
Second-order effects
Google’s later data showing espionage actors used 48 of 97 observed 2023 zero days reinforces that state-linked operators, rather than financially motivated groups alone, must be central to zero-day defense planning.
The growing volume of observed exploitation increases the value of rapid discovery and disclosure work: Project Zero attributed its 2021 record in part to improved industry detection.
Third-order effects
The pattern points to zero-day exploitation becoming a durable feature of state-aligned and commercial surveillance operations, even as annual totals fluctuate; Google later tracked 90 exploited zero days in 2025.
Security competition increasingly hinges on the ability to detect live exploitation and turn those observations into patches and public intelligence, not solely on preventing vulnerabilities from existing.
The trend: Zero-day defense is shifting toward continuous exploitation tracking as state-linked and commercial spyware actors sustain demand for previously unknown flaws.
Google's @ShaneHuntley tells me the suspected Russian hackers who exploited the Apple WebKit zero-day outlined here https://blog.google/... was more specifically the same group behind the USAID impersonation phishing campaign — e.g., Russian foreign intelligence. More from Shane:…
Post by @_clem1 & @maddiestone on 4 0days TAG found this year (with IOCs!). We tie three to a commercial surveillance vendor arming govt backed attackers and one to likely Russian APT. Also thoughts on why we are seeing so many 0day in 2021. https://blog.google/... https://twitte…
More details about the 4 in-the-wild 0-day exploits that Google's Threat Analysis Group has discovered this year as well as our thoughts on the uptick in in-the-wild 0-days we're seeing this year. @_clem1 https://blog.google/...
NEW: Google found that some LinkedIn messages sent to European government officials led to a zero-day exploit to steal their authentication cookies. Company believes hackers were “likely Russian government-backed.” https://www.vice.com/...
These are two different campaigns, but based on our visibility, we consider the actors behind the WebKit 0-day and the USAID campaign to be the same group of actors. https://arstechnica.com/...
“exploit would turn off Same-Origin-Policy protections in order to collect authentication cookies from several popular websites, including Google, Microsoft, LinkedIn, Facebook and Yahoo and send them via WebSocket to an attacker-controlled IP” https://blog.google/... https://twi…
A fourth zero-day was used by a Russian cyber-espionage group (most likely APT29) to target western European government officials via LinkedIn Dedicated report here: https://twitter.com/...
Attackers taking advantage of missing Site Isolation in WebKit. That makes sense for them because all browsers on iOS uses WebKit 🙄Clearly, Apple is behind in the game of Site Isolation and it's impacting users even outside Safari. https://blog.google/...
UPDATE: Google Threat Analysis Group director @ShaneHuntley says they don't know how many people were successfully hacked in this campaign. But he says Google normally sends around 4,000 warnings to users targeted by government hackers. https://www.vice.com/... https://twitter.co…
Additional information/context from TAG regarding the WebKit vulnerability (CVE-2021-1879) leveraged by #NOBELIUM during their email-based attacks (https://www.microsoft.com/...): https://blog.google/... https://twitter.com/...
“Russian government hackers targeted European government officials with LinkedIn messages that contained malicious links designed to exploit unknown vulnerabilities in Windows and iOS, according to Google's report” https://www.vice.com/... https://blog.google/... https://twitter.…
We're also publishing root cause analyses for the four 0-days: Chrome CVE-2021-21166: https://googleprojectzero.github.io/ ... Chrome CVE-2021-30551: https://googleprojectzero.github.io/ ... Internet Explorer CVE-2021-33742: https://googleprojectzero.github.io/ ... Safari CVE-202…
For the past few months, I've had the honor to work within both Google TAG and Project Zero on the 0-days in-the-wild program. I'm excited to share with y'all the good stuff we've done and will continue to do on the TAG side 🤗