Google's Threat Analysis Group details two limited but highly targeted spyware campaigns using several zero-day exploits against Android, iOS, and Chrome
Two targeted spyware campaigns involving several zero-day exploits for Android, iOS and mobile versions of the Chrome browser were unmasked …
The significance is less the scale of the campaigns than the breadth of the exploit chains: Android, iOS, and mobile Chrome are treated as connected high-value targets rather than separate security domains.
First-order effects
People selected by the campaigns face immediate risk across Android, iOS, and mobile Chrome where the disclosed zero-days were used.
Google and the affected platform teams must turn Threat Analysis Group findings into remediation and detection work for several exploit paths, rather than a single-product fix.
Second-order effects
Attackers using comparable chains may change infrastructure, delivery methods, or exploits once the campaigns’ tactics are exposed, shortening the useful life of the disclosed techniques.
The cross-platform nature of the campaigns raises the value of coordination among mobile OS and browser security teams, since a target’s device and browser can be part of the same intrusion path.
Third-order effects
If targeted operators continue to assemble zero-day chains across mobile platforms and browsers, security competition will increasingly center on rapid cross-product detection and patching rather than isolated vulnerability response.
Repeated public attribution of spyware activity may improve defensive visibility, but it also underscores that highly targeted intrusion capability can persist even when broad user exposure is limited.
The trend: This is one data point in the continuing professionalization of targeted spyware operations that combine browser and mobile zero-days into multi-surface surveillance chains.
New from Google: Details about two distinct campaigns we've recently discovered which used various 0-day exploits against Android, iOS and Chrome and were both limited and highly targeted https://blog.google/...
NEW 📢 Amnesty's Security Lab uncovers hacking campaign targeting Android users with zero-day exploits. Attack had all the hallmarks of an advanced spyware campaign by a commercial cyber-surveillance company sold to government hackers. 1/5 https://www.amnesty.org/...
Spyware crisis: Another sophisticated hacking campaign exposed - “merely a sticking plaster to a global spyware crisis” https://www.amnesty.org/... #Staatstrojaner
Just in case you think the proliferation of spyware companies is strictly an Israeli problem, here is Variston, which is based on Spain. https://twitter.com/...
New @Google TAG blog highlights 2 campaigns that build on their work to track commercial spyware vendors. Proud of the important work done by @ShaneHuntley and the team to expose these vulnerabilities. https://blog.google/...
Another mercenary spyware vendor caught in the wild; Indicators shared with @Google's TAG, and patches rolled out... Great work @AmnestyTech @DonnchaC 👇 Amnesty International uncovers new hacking campaign linked to mercenary spyware company https://www.amnesty.org/...
✨Amazing detection and analysis by @_clem1 and Google TAG on 2 different campaigns using 5 different 0-days and numerous n-days. Android, iOS, and Samsung devices were targeted https://blog.google/... https://twitter.com/...
Google finds more Android, iOS zero-days used to install spyware : https://blog.google/... Ref : 1) https://googleprojectzero.blogspot.com/ ... 2 ) Pwning the all Google phone with a non-Google bug : https://github.blog/...
“Even smaller surveillance vendors have access to 0-days, and vendors stockpiling and using 0-day vulnerabilities in secret poses a severe risk to the Internet,” said @Google's Threat Analysis Group researchers. https://scoopmedia.co/3Zqin2I