/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google says Russia-linked APT29 is using exploits that are “identical or strikingly similar” to those previously made by spyware makers Intellexa and NSO Group

«Russian government hackers found using #exploits made by spyware companies NSO and Intellexa: … Frederic Jacobs / @fj@mastodon.social : “Our latest n-day exploit reporting shows that in an attack on Mongolian government websites, Russian-backed APT29 is suspected of using the same exploits as Intellexa and NSO”  —  https://blog.google/... Zack Whittaker / @zackwhittaker@mastodon.social : New, by me: Google's Threat Analysis Group found evidence that a group of Russian government hackers, aka APT29, are using exploits that are “identical or strikingly similar” to those previously made by spyware makers Intellexa and NSO Group. … X: John Scott-Railton / @jsrailton : BIG DEAL: Russia caught reusing phone exploit strikingly similar to NSO Group's Pegasus spyware. How did Russian Intelligence / #APT29 get it after NSO used it? Google isn't sure yet. But I warned Congress this would happen. It says something about who NSO sourced it from, [video] Lorenzo Franceschi-Bicchierai / @lorenzofb : NEW: Google found evidence that a group of Russian government hackers, aka APT29, are using exploits that are “identical or strikingly similar” to those previously made by spyware makers Intellexa and NSO Group. https://techcrunch.com/... Dan Black / @danwblack : Important report highlighting the SVR's wider enablers: “In each iteration of the watering hole campaigns, [APT29] used exploits that were identical or strikingly similar to exploits previously used by commercial surveillance vendors Intellexa and NSO Group.” Charley Snyder / @charley_snyder_ : Noteworthy new research here on APT29 use of old NSO and Intellexa exploits. In my opinion, this is yet more evidence that the proliferation of commercial hacking capabilities — sometimes into the hands of apex teams like APT29 — poses a serious threat to the web. Adam Rawnsley / @arawnsley : “In each iteration of the watering hole campaigns, the attackers used exploits that were identical or strikingly similar to exploits previously used by commercial surveillance vendors (CSVs) Intellexa and NSO Group.” https://blog.google/... Will / @bushidotoken : Latest 🇷🇺 APT29 (Cozy Bear, Midnight Blizzard) activity below 👇 Billy Leonard / @billyleonard : 🆕🚨 New analysis from @Google TAG on suspected APT29 waterholes against 🇲🇳 gov. n-day exploits targeting iOS and Android we first observed in use from commercial surveillance vendors🫢 more details in the blog! awesome work from @_clem1 and team🤝 https://blog.google/... LinkedIn: Matthias Frielingsdorf : Today Google TAG revealed details about an attack against both Android and iOS devices.  The attackers were targeting Safari & Google Chrome with previously already patched vulnerabilities (N-Days). …

TechCrunch Zack Whittaker

Context & Ripple Effects

Google’s threat researchers had already documented a broad commercial-spyware market and called for stronger government action in a survey of roughly 40 spyware vendors. Earlier reporting also showed how targeted mobile spyware campaigns could rely on multiple zero-days, including campaigns targeting Android, iOS, and Chrome.

This report matters because it places exploit capabilities associated with commercial vendors in a state-linked intrusion context. Similarity of exploits is evidence for defenders and investigators, but it does not by itself establish how APT29 obtained them or prove vendor involvement.

First-order effects

  • Organizations exposed to the reported watering-hole activity can use Google’s findings to prioritize investigation, patching, and detection for the implicated exploit techniques.
  • Intellexa and NSO face renewed scrutiny over where capabilities associated with their products may surface, while Google’s attribution work becomes actionable threat intelligence for likely targets.

Second-order effects

  • Platform security teams and incident responders may treat commercial-spyware research as a more direct input to state-threat defense; prior mobile exploit cases have required rapid vendor patching, such as Apple’s patches for Triangulation-exploited zero-days.
  • Governments assessing spyware vendors gain another reason to demand tighter controls and transparency, even though exploit similarity alone does not identify a supply path or responsible party.

Third-order effects

  • If commercial exploit techniques continue to appear in state-linked operations, the practical boundary between mercenary surveillance tooling and government cyber capability will erode further.
  • That convergence could shift scrutiny from individual spyware deployments toward the full exploit supply chain—developers, brokers, customers, and vulnerability-handling practices—though this report alone cannot establish the scale of that overlap.

The trend: Commercial spyware capabilities are increasingly being treated as dual-use cyber infrastructure whose reuse or replication can amplify state-backed operations.

Discussion

  • @fj@mastodon.social Frederic Jacobs on mastodon
    “Our latest n-day exploit reporting shows that in an attack on Mongolian government websites, Russian-backed APT29 is suspected of using the same exploits as Intellexa and NSO”  —  https://blog.google/...
  • @zackwhittaker@mastodon.social Zack Whittaker on mastodon
    New, by me: Google's Threat Analysis Group found evidence that a group of Russian government hackers, aka APT29, are using exploits that are “identical or strikingly similar” to those previously made by spyware makers Intellexa and NSO Group. …
  • @jsrailton John Scott-Railton on x
    BIG DEAL: Russia caught reusing phone exploit strikingly similar to NSO Group's Pegasus spyware. How did Russian Intelligence / #APT29 get it after NSO used it? Google isn't sure yet. But I warned Congress this would happen. It says something about who NSO sourced it from, [video…
  • @lorenzofb Lorenzo Franceschi-Bicchierai on x
    NEW: Google found evidence that a group of Russian government hackers, aka APT29, are using exploits that are “identical or strikingly similar” to those previously made by spyware makers Intellexa and NSO Group. https://techcrunch.com/...
  • @danwblack Dan Black on x
    Important report highlighting the SVR's wider enablers: “In each iteration of the watering hole campaigns, [APT29] used exploits that were identical or strikingly similar to exploits previously used by commercial surveillance vendors Intellexa and NSO Group.”
  • @charley_snyder_ Charley Snyder on x
    Noteworthy new research here on APT29 use of old NSO and Intellexa exploits. In my opinion, this is yet more evidence that the proliferation of commercial hacking capabilities — sometimes into the hands of apex teams like APT29 — poses a serious threat to the web.
  • @arawnsley Adam Rawnsley on x
    “In each iteration of the watering hole campaigns, the attackers used exploits that were identical or strikingly similar to exploits previously used by commercial surveillance vendors (CSVs) Intellexa and NSO Group.” https://blog.google/...
  • @bushidotoken Will on x
    Latest 🇷🇺 APT29 (Cozy Bear, Midnight Blizzard) activity below 👇
  • @billyleonard Billy Leonard on x
    🆕🚨 New analysis from @Google TAG on suspected APT29 waterholes against 🇲🇳 gov. n-day exploits targeting iOS and Android we first observed in use from commercial surveillance vendors🫢 more details in the blog! awesome work from @_clem1 and team🤝 https://blog.google/...