Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • We Have Hundreds of Blockchain Patents — But Regulation Won’t Allow Us to Engage in Crypto – Regulation Bitcoin News bitcoin news
  • Conti Cybercrime Cartel Using ‘BazarCall’ Phishing Attacks as Initial Attack Vector cyber security news
  • Acquiring a Home With Bitcoin — A Deep Dive Into the Latest Crypto-Backed Mortgage Trend – Bitcoin News bitcoin news
  • Bitcoin Miner Revenues Continue To Grow, Will This Put A Stop To The Sell-Offs? bitcoin news
  • Yes, Containers Are Terrific, But Watch the Security Risks cyber security news
  • Do Kwon Accused of Cashing out $2.7B Before UST Collapse, Terra Founder Says Allegations Are False – Bitcoin News bitcoin news
  • Bitcoin Taker Buy/Sell Ratio Approaches Bullish Cross bitcoin news
  • Emergency Alert System Flaws Could Let Attackers Transmit Fake Messages cyber security news

Candiru Spyware Caught Exploiting Google Chrome Zero-Day to Target Journalists

Posted on July 22, 2022 By root


Candiru Spyware Chrome Exploit

The actively exploited but now-fixed Google Chrome zero-day flaw that came to light earlier this month was weaponized by an Israeli spyware company and used in attacks targeting journalists in the Middle East.

Czech cybersecurity firm Avast linked the exploitation to Candiru (aka Saito Tech), which has a history of leveraging previously unknown flaws to deploy a Windows malware dubbed DevilsTongue, a modular implant with Pegasus-like capabilities.

Candiru, along with NSO Group, Computer Security Initiative Consultancy PTE. LTD., and Positive Technologies, were added to the entity list by the U.S. Commerce Department in November 2021 for engaging in “malicious cyber activities.”

“Specifically, a large portion of the attacks took place in Lebanon, where journalists were among the targeted parties,” security researcher Jan Vojtěšek, who reported the discovery of the flaw, said in a write-up. “We believe the attacks were highly targeted.”

CyberSecurity

The vulnerability in question is CVE-2022-2294, memory corruption in the WebRTC component of the Google Chrome browser that could lead to shellcode execution. It was addressed by Google on July 4, 2022. The same issue has since been patched by Apple and Microsoft in Safari and Edge browsers.

The findings shed light on multiple attack campaigns mounted by the Israeli hack-for-hire vendor, which is said to have returned with a revamped toolset in March 2022 to target users in Lebanon, Turkey, Yemen, and Palestine via watering hole attacks using zero-day exploits for Google Chrome.

Candiru Spyware

The infection sequence spotted in Lebanon commenced with the attackers compromising a website used by employees of a news agency to inject malicious JavaScript code from an actor-controlled domain that’s responsible for redirecting potential victims to an exploit server.

Via this watering hole technique, a profile of the victim’s browser, consisting of about 50 data points, is created, including details like language, timezone, screen information, device type, browser plugins, referrer, and device memory, among others.

Avast assessed the information was gathered to ensure that the exploit was being delivered only to the intended targets. Should the collected data be deemed of value by the hackers, the zero-day exploit is then delivered to the victim’s machine over an encrypted channel.

CyberSecurity

The exploit, in turn, abuses the heap buffer overflow in WebRTC to attain shellcode execution. The zero-day flaw is said to have been chained with a sandbox escape exploit (that was never recovered) to gain an initial foothold, using it to drop the DevilsTongue payload.

While the sophisticated malware is capable of recording the victim’s webcam and microphone, keylogging, exfiltrating messages, browsing history, passwords, locations, and much more, it has also been observed attempting to escalate its privileges by installing a vulnerable signed kernel driver (“HW.sys“) containing a third zero-day exploit.

Earlier this January, ESET explained how vulnerable signed kernel drivers – an approach called Bring Your Own Vulnerable Driver (BYOVD) – can become unguarded gateways for malicious actors to gain entrenched access to Windows machines.

The disclosure comes a week after Proofpoint revealed that nation-state hacking groups aligned with China, Iran, North Korea, and Turkey have been targeting journalists to conduct espionage and spread malware since early 2021.





TheHackersNews/

cyber security news

Post navigation

Previous Post: Ukrainian Radio Stations Hacked to Broadcast Fake News About President Zelensky’s Health
Next Post: Avalanche Sustains 7-Day Upswing – Can AVAX Easily Breach $26?

Related Posts

  • Cisco Confirms It’s Been Hacked by Yanluowang Ransomware Gang cyber security news
  • Hello XD Ransomware Installing Backdoor on Targeted Windows and Linux Systems cyber security news
  • Indian Govt Orders Organizations to Report Security Breaches Within 6 Hours to CERT-In cyber security news
  • New Hertzbleed Side-Channel Attack Affects All Modern AMD and Intel CPUs cyber security news
  • SEC Plans to Hire More Staff in Crypto Enforcement Unit to Fight Frauds cyber security news
  • Critical ‘Pantsdown’ BMC Vulnerability Affects QCT Servers Used in Data Centers cyber security news

Archives

  • August 2022
  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Researchers Uncover UEFI Secure Boot Bypass in 3 Microsoft Signed Boot Loaders
  • Bitcoin Is An alternative To Economic Condition, Says CEO Of Franklin
  • Bitcoin’s Mathematical Monetary Policy Is Far More Predictable Than Gold and Fiat Currencies – Economics Bitcoin News
  • New Findings Shows Institutional Investors Take More Interest In Ethereum
  • Whales With 1k-10k BTC Depositing To Exchanges

Recent Comments

No comments to show.
  • Crypto-Related Lawsuits Rising in Russia, Criminal Cases Increase by 40% – Bitcoin News bitcoin news
  • Microstrategy Outperforms Every Asset Class and Big Tech Stock Since Adopting Bitcoin Strategy, Says CEO – Featured Bitcoin News bitcoin news
  • Metaverse Project Genso Closed Beta Test Date and Details Released – Press release Bitcoin News bitcoin news
  • The Fed’s Christopher Waller Wants 50 bps Rate Hikes Until Inflation Subsides, US Savings Data Plummets – Economics Bitcoin News bitcoin news
  • Ethereum Gas Fees Touch New Lows, What’s Ahead For Ethereum bitcoin news
  • Ripple XRP Ledger Co-Creator Stops The Selling Spree, Bullish Trend Nearby? bitcoin news
  • Bitcoin Records Worst Performance For June, Will It Get Better From Here? bitcoin news
  • Shiba Inu Breaks Downtrend Line – Is A Trend Reversal Imminent? bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme