• Home
  • Shop
  • Privacy Policy
  • Terms and Conditions
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Hackers used 4 zero-days to infect Windows and Android devices

January 13, 2021
Share on FacebookShare on Twitter

Google researchers have detailed a sophisticated hacking operation that exploited vulnerabilities in Chrome and Windows to install malware on Android and Windows devices.

Some of the exploits were zero-days, meaning they targeted vulnerabilities that at the time were unknown to Google, Microsoft, and most outside researchers (both companies have since patched the security flaws). The hackers delivered the exploits through watering-hole attacks, which compromise sites frequented by the targets of interest and lace the sites with code that installs malware on visitors’ devices. The boobytrapped sites made use of two exploit servers, one for Windows users and the other for users of Android.

Not your average hackers

The use of zero-days and complex infrastructure isn’t in itself a sign of sophistication, but it does show above-average skill by a professional team of hackers. Combined with the robustness of the attack code—which chained together multiple exploits in an efficient manner—the campaign demonstrates it was carried out by a “highly sophisticated actor.”

“These exploit chains are designed for efficiency & flexibility through their modularity,” a researcher with Google’s Project Zero exploit research team wrote. “They are well-engineered, complex code with a variety of novel exploitation methods, mature logging, sophisticated and calculated post-exploitation techniques, and high volumes of anti-analysis and targeting checks. We believe that teams of experts have designed and developed these exploit chains.”

Advertisement

The modularity of the payloads, the interchangeable exploit chains, and the logging, targeting, and maturity of the operation also set the campaign apart, the researcher said.

The four zero-days exploited were:

  • CVE-2020-6418—Chrome Vulnerability in TurboFan (fixed February 2020)
  • CVE-2020-0938—Font Vulnerability on Windows (fixed April 2020)
  • CVE-2020-1020—Font Vulnerability on Windows (fixed April 2020)
  • CVE-2020-1027—Windows CSRSS Vulnerability (fixed April 2020)

The attackers obtained remote code execution by exploiting the Chrome zero-day and several recently patched Chrome vulnerabilities. All of the zero-days were used against Windows users. None of the attack chains targeting Android devices exploited zero-days, but the Project Zero researchers said it’s likely the attackers had Android zero-days at their disposal.

The diagram below provides a visual overview of the the campaign, which occurred in the first quarter of last year:

Google

In all, Project Zero published six installments detailing the exploits and post-exploit payloads the researchers found. Other parts outline a Chrome infinity bug, the Chrome exploits, the Android exploits, the post-Android exploitation payloads, and the Windows exploits.

The intention of the series is to assist the security community at large in more effectively combating complex malware operations. “We hope this blog post series provides others with an in-depth look at exploitation from a real-world, mature, and presumably well-resourced actor,” Project Zero researchers wrote.

Next Post

Google fixes loading issue with COVID-19 tracking apps

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Click Here!

Recent News.

Fossil Gen 5 LTE smartwatch announced (Updated)

January 21, 2021

Tom Hanks Sci-Fi Drama Bios Has Been Delayed To August

January 21, 2021

EV buyers likely to buy another, but brand loyalty less likely, J.D. Power says

January 21, 2021

Nuki smart locks drop support for using old Android devices as network hubs

January 21, 2021

Mobile .

Bodyguard is a mobile app that hides toxic content on social platforms – TechCrunch

January 21, 2021

Camera refinements are nice, but the price drop’s the thing – TechCrunch

January 21, 2021

6 investors on 2021’s mobile gaming trends and opportunities – TechCrunch

January 19, 2021

Apple’s new editorial franchise, Apple Podcasts Spotlight, to highlight interesting creators – TechCrunch

January 19, 2021

Recent News

Fossil Gen 5 LTE smartwatch announced (Updated)

January 21, 2021

Tom Hanks Sci-Fi Drama Bios Has Been Delayed To August

January 21, 2021

Sci-Fi

This AI can tell if you have prostate cancer by looking at your pee

January 21, 2021
No Result
View All Result

Categories

  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
  • Home
  • Shop
  • Privacy Policy
  • Terms and Conditions

© CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi

© CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

Get more stuff like this
in your inbox

Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

Thank you for subscribing.

Something went wrong.

We respect your privacy and take protecting it seriously