Top Russian APT Has a Copycat Among Commercial Spyware Vendors

Published:

spot_img

Russian-Backed Threat Actor APT29 Linked to Multiple Exploit Campaigns Delivering N-day Mobile Exploits

A recent discovery by Google’s Threat Analysis Group (TAG) has uncovered multiple exploit campaigns linked to a Russian-backed threat actor known as APT29, Cozy Bear, and Midnight Blizzard. These campaigns were found to be delivering n-day mobile exploits that had been previously used by commercial spyware vendors.

The exploit campaigns were carried out through a watering hole attack on Mongolian government websites, specifically targeting cabinet.gov.mn and mfa.gov.mn. By injecting code to exploit known vulnerabilities in iOS and Chrome on Android, the threat actors aimed to compromise visitors’ devices.

Researchers at Google TAG noted that the exploits used in these campaigns were identical to those employed by commercial surveillance vendors Intellexa and NSO Group, indicating a potential connection between the authors and providers.

Despite the patches released for the vulnerabilities, the exploit campaigns resurfaced on three separate occasions, with the latest attack occurring just a month ago. The researchers emphasized the concerning trend of threat actors repurposing exploits originally developed by the commercial surveillance industry for malicious purposes.

While the source of these exploits remains unclear, the incident underscores the increasing threat posed by the reuse of exploits by malicious actors. As the cybersecurity landscape continues to evolve, vigilance and collaboration among researchers, industry, and governments will be crucial in mitigating these risks.

spot_img

Related articles

Recent articles

Crocodilus Android Trojan Targets Banks and Crypto Wallets in 8 Countries

Rising Threats: The Crocodilus Android Banking Trojan Introduction to Crocodilus A newly identified Android banking trojan, dubbed Crocodilus, is making waves among cybersecurity experts as it...

Sharjah Chamber to Celebrate Excellence Award Winners on June 25

Sharjah Excellence Award 2024: Ceremony Date and Upcoming Developments Upcoming Closing Ceremony The Sharjah Excellence Award (SEA) is set to host its closing ceremony, recognizing the...

Uncovering Malicious Packages: The Ongoing Threat to Open-Source Supply Chains

Rising Threats in Open-Source Ecosystems: An Insight into Malicious Packages In recent weeks, significant concerns have emerged regarding the integrity of open-source ecosystems, particularly within...

Inside the Dark Web: Infiltrating Ransomware Gangs

Understanding the Ransomware Crisis: Insights from 60 Minutes In a recent segment of 60 Minutes, correspondent Bill Whitaker delved into the escalating threat of ransomware...