Go to listing page

Zero-day Flaws Used in Nine Months Long Campaign Targeting Windows, iOS, and Android Devices

Zero-day Flaws Used in Nine Months Long Campaign Targeting Windows, iOS, and Android Devices
So, what do we have here? We have multiple zero-day flaws. A months-long attack campaign. And a group of exceptionally sophisticated hackers.

The scoop

A threat actor group exploited 11 zero-day vulnerabilities in a campaign that lasted for nine sweet months. This attack leveraged compromised websites to infect fully patched devices running iOS, Android, and Windows.

A bit of backstory


About the attack

  • All the exploits were propagated via watering hole attacks that redirected targets to an infrastructure that installed diverse malware depending on the browsers and devices.
  • While the two servers spotted in February exploited only Windows and Android, the latter one targeted iOS devices too.

The bottom line

As of now, the threat actor responsible for these exploits is unknown, along with the number of people affected. This incident only further highlights the importance of keeping apps and operating software updated and patched. However, what’s jarring is that none of these defenses could have protected anyone from these attackers.

Cyware Publisher

Publisher

Cyware