{"id":1800,"date":"2023-09-29T18:43:00","date_gmt":"2023-09-29T18:43:00","guid":{"rendered":"https:\/\/www.darkreading.com\/dr-global\/spyware-vendor-egyptian-orgs-ios-exploit-chain"},"modified":"2023-09-29T18:43:00","modified_gmt":"2023-09-29T18:43:00","slug":"spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/09\/29\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain\/","title":{"rendered":"Spyware Vendor Targets Egyptian Orgs With Rare iOS Exploit Chain"},"content":{"rendered":"<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?w=640&#038;ssl=1\"><\/p>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain-1.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p>An Israeli surveillanceware company used the three Apple zero-day vulnerabilities disclosed last week to develop an exploit chain for iPhones, and a Chrome zero-day to exploit Androids \u2014 all in a novel attack on Egyptian organizations.<\/p>\n<p><a href=\"https:\/\/blog.google\/threat-analysis-group\/0-days-exploited-by-commercial-surveillance-vendor-in-egypt\/\" target=\"_blank\" rel=\"noopener\">According to a recent report<\/a> from Google&#8217;s Threat Analysis Group (TAG), <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/receipt-8m-ios-zero-day-sale-dark-web\" target=\"_blank\" rel=\"noopener\">the company \u2014 which calls itself &#8220;Intellexa&#8221;<\/a> \u2014 used the special access it gained through the exploit chain&nbsp;to install its signature &#8220;Predator&#8221; spyware against unnamed targets in Egypt.<\/p>\n<p>Predator was first developed by Cytrox, one of a number of spyware developers that have been&nbsp;absorbed under the umbrella of Intellexa in recent years, according to TAG. The company is a known threat:&nbsp;<a href=\"https:\/\/citizenlab.ca\/2021\/12\/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware\/\" target=\"_blank\" rel=\"noopener\">Intellexa had previously deployed Predator<\/a> against Egyptian citizens back in 2021.<\/p>\n<p>Intellexa&#8217;s iPhone infections in Egypt began with man-in-the-middle (MITM) attacks, intercepting users as they attempted to reach http sites (encrypted https requests were immune).<\/p>\n<p>&#8220;The use of MITM injection gives the attacker a capability where they don&#8217;t have to rely on the user to take a typical action like clicking a specific link, opening a document, etc.,&#8221; TAG researchers note via email. &#8220;This is similar to zero-click exploits, but without having to find a vulnerability in a zero-click attack surface.&#8221;<\/p>\n<p>They added, &#8220;this is yet another example of the harms caused by commercial surveillance vendors and the threats they pose not only to individuals, but society at large.&#8221;<\/p>\n<h2 class=\"regular-text\">3 Zero-Days in iOS, 1 Attack Chain<\/h2>\n<p>Using the MITM gambit, users were redirected to an attacker-controlled site. From there, if the ensnared user was the intended target \u2014 each attack being aimed only at specific individuals \u2014 they would be redirected to a second domain, where the exploit would trigger.<\/p>\n<p>Intellexa&#8217;s exploit chain involved three zero-day<a href=\"https:\/\/www.darkreading.com\/application-security\/apple-fixes-3-more-zero-day-vulnerabilities\" target=\"_blank\" rel=\"noopener\">&nbsp;vulnerabilities, which have been patched<\/a> as of iOS 17.0.1. They&#8217;re&nbsp;tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-41992\" target=\"_blank\" rel=\"noopener\">CVE-2023-41993<\/a> \u2014 a remote code execution (RCE) bug in Safari;&nbsp;<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-41991\" target=\"_blank\" rel=\"noopener\">CVE-2023-41991<\/a> \u2014 a certificate validation issue allowing for PAC bypass;&nbsp;and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-41992\" target=\"_blank\" rel=\"noopener\">CVE-2023-41992<\/a> \u2014 which enables privilege escalation in the device kernel.<\/p>\n<p>After all three steps were complete, a small binary would determine whether to drop the Predator malware.<\/p>\n<p>&#8220;The finding of a full zero-day exploit chain for iOS is typically novel in learning what&#8217;s currently cutting edge for attackers. Each time a zero-day exploit is caught in-the-wild, it&#8217;s the failure case for attackers \u2014 they don&#8217;t want us to know what vulnerabilities they have and how their exploits work,&#8221; the researchers noted in the email. &#8220;As a security and tech industry, it&#8217;s our job to learn as much as we can about these exploits to make it that much harder for them to create a new one.&#8221;<\/p>\n<h2 class=\"regular-text\">A Singular Vulnerability in Android<\/h2>\n<p>In addition to iOS, Intellexa targeted Android phones via MITM and one-time links sent directly to targets.&nbsp;<\/p>\n<p>This time only one vulnerability was needed: <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-4762\" target=\"_blank\" rel=\"noopener\">CVE-2023-4762<\/a>, high-severity but rating&nbsp;8.8 out of 10 on the CVSS vulnerability-severity scale. The flaw <a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/chrome-flags-third-zero-day-this-month-tied-to-spying-exploits\" target=\"_blank\" rel=\"noopener\">exists in&nbsp;Google Chrome<\/a> and enables attackers to execute arbitrary code on a host machine via a specially crafted HTML page. Independently reported by a security researcher and patched as of Sept. 5, Google TAG believes Intellexa was previously using the vulnerability as a zero-day.<\/p>\n<p>The good news is the&nbsp;findings will send would-be attackers back to the drawing board, according to Google TAG.&nbsp;<\/p>\n<p>&#8220;The attackers will now have to replace four of their zero-day exploits, which means they have to buy or develop new exploits to maintain their ability to install Predator on iPhones,&#8221; the researchers emailed. &#8220;Each time their exploits are caught in the wild, it costs attackers money, time, and resources.&#8221;<\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/dr-global\/spyware-vendor-egyptian-orgs-ios-exploit-chain\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An Israeli surveillanceware company used the three Apple zero-day vulnerabilities<\/p>\n","protected":false},"author":12,"featured_media":1801,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-1800","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?fit=881%2C923&ssl=1",881,923,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?fit=286%2C300&ssl=1",286,300,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?fit=640%2C671&ssl=1",640,671,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?fit=640%2C671&ssl=1",640,671,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?fit=881%2C923&ssl=1",881,923,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?fit=881%2C923&ssl=1",881,923,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?fit=881%2C923&ssl=1",881,923,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/spyware-vendor-targets-egyptian-orgs-with-rare-ios-exploit-chain.jpg?fit=881%2C923&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1800"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1800\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/1801"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}