Russian Government Hackers Found Using Exploits Made By Spyware Companies NSO and Intellexa

russian-government-hackers-found-using-exploits-made-by-spyware-companies-nso-and-intellexa
Russian Government Hackers Found Using Exploits Made By Spyware Companies NSO and Intellexa

Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

Posted by msmash from the security-woes dept.

Google says it has evidence that Russian government hackers are using exploits that are “identical or strikingly similar” to those previously made by spyware makers Intellexa and NSO Group. From a report: In a blog post on Thursday, Google said it is not sure how the Russian government acquired the exploits, but said this is an example of how exploits developed by spyware makers can end up in the hands of “dangerous threat actors.” In this case, Google says the threat actors are APT29, a group of hackers widely attributed to Russia’s Foreign Intelligence Service, or the SVR. APT29 is a highly capable group of hackers, known for its long-running and persistent campaigns aimed at conducting espionage and data theft against a range of targets, including tech giants Microsoft and SolarWinds, as well as foreign governments.

Google said it found the hidden exploit code embedded on Mongolian government websites between November 2023 and July 2024. During this time, anyone who visited these sites using an iPhone or Android device could have had their phone hacked and data stolen, including passwords, in what is known as a “watering hole” attack. The exploits took advantage of vulnerabilities in the iPhone’s Safari browser and Google Chrome on Android that had already been fixed at the time of the suspected Russian campaign. Still, those exploits nevertheless could be effective in compromising unpatched devices.

I don’t want to achieve immortality through my work. I want to achieve immortality through not dying. — Woody Allen

Working…