/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google's Threat Analysis Group details two limited but highly targeted spyware campaigns using several zero-day exploits against Android, iOS, and Chrome

Two targeted spyware campaigns involving several zero-day exploits for Android, iOS and mobile versions of the Chrome browser were unmasked …

The Record Jonathan Greig

Context & Ripple Effects

Google’s Threat Analysis Group had already traced Predator spyware campaigns exploiting Android flaws and later documented Hermit targeting both Android and iOS. This report extends that coverage from individual spyware families to multiple tightly scoped campaigns using zero-days across the major mobile and browser surfaces.

The significance is less the scale of the campaigns than the breadth of the exploit chains: Android, iOS, and mobile Chrome are treated as connected high-value targets rather than separate security domains.

First-order effects

  • People selected by the campaigns face immediate risk across Android, iOS, and mobile Chrome where the disclosed zero-days were used.
  • Google and the affected platform teams must turn Threat Analysis Group findings into remediation and detection work for several exploit paths, rather than a single-product fix.

Second-order effects

  • Attackers using comparable chains may change infrastructure, delivery methods, or exploits once the campaigns’ tactics are exposed, shortening the useful life of the disclosed techniques.
  • The cross-platform nature of the campaigns raises the value of coordination among mobile OS and browser security teams, since a target’s device and browser can be part of the same intrusion path.

Third-order effects

  • If targeted operators continue to assemble zero-day chains across mobile platforms and browsers, security competition will increasingly center on rapid cross-product detection and patching rather than isolated vulnerability response.
  • Repeated public attribution of spyware activity may improve defensive visibility, but it also underscores that highly targeted intrusion capability can persist even when broad user exposure is limited.

The trend: This is one data point in the continuing professionalization of targeted spyware operations that combine browser and mobile zero-days into multi-surface surveillance chains.

Discussion

  • @ryanaraine Ryan Naraine on x
    New from Google: Details about two distinct campaigns we've recently discovered which used various 0-day exploits against Android, iOS and Chrome and were both limited and highly targeted https://blog.google/...
  • @amnestytech @amnestytech on x
    NEW 📢 Amnesty's Security Lab uncovers hacking campaign targeting Android users with zero-day exploits. Attack had all the hallmarks of an advanced spyware campaign by a commercial cyber-surveillance company sold to government hackers. 1/5 https://www.amnesty.org/...
  • @chaosupdates @chaosupdates on x
    Spyware crisis: Another sophisticated hacking campaign exposed - “merely a sticking plaster to a global spyware crisis” https://www.amnesty.org/... #Staatstrojaner
  • @evacide Eva on x
    Just in case you think the proliferation of spyware companies is strictly an Israeli problem, here is Variston, which is based on Spain. https://twitter.com/...
  • @royalhansen @royalhansen on x
    New @Google TAG blog highlights 2 campaigns that build on their work to track commercial spyware vendors. Proud of the important work done by @ShaneHuntley and the team to expose these vulnerabilities. https://blog.google/...
  • @rondeibert @rondeibert on x
    Another mercenary spyware vendor caught in the wild; Indicators shared with @Google's TAG, and patches rolled out... Great work @AmnestyTech @DonnchaC 👇 Amnesty International uncovers new hacking campaign linked to mercenary spyware company https://www.amnesty.org/...
  • @maddiestone Maddie Stone on x
    ✨Amazing detection and analysis by @_clem1 and Google TAG on 2 different campaigns using 5 different 0-days and numerous n-days. Android, iOS, and Samsung devices were targeted https://blog.google/... https://twitter.com/...
  • @binitamshah Binni Shah on x
    Google finds more Android, iOS zero-days used to install spyware : https://blog.google/... Ref : 1) https://googleprojectzero.blogspot.com/ ... 2 ) Pwning the all Google phone with a non-Google bug : https://github.blog/...
  • @cyberscoopnews @cyberscoopnews on x
    “Even smaller surveillance vendors have access to 0-days, and vendors stockpiling and using 0-day vulnerabilities in secret poses a severe risk to the Internet,” said @Google's Threat Analysis Group researchers. https://scoopmedia.co/3Zqin2I