Security News > 2021 > January > Sophisticated Hacks Against Android, Windows Reveal Zero-Day Trove

Sophisticated Hacks Against Android, Windows Reveal Zero-Day Trove
2021-01-13 16:57

Google researchers have detailed a major hacking campaign that was detected in early 2020, which mounted a series of sophisticated attacks, some using zero-day flaws, against Windows and Android platforms.

Working together, researchers from Google Project Zero and the Google Threat Analysis Group uncovered the attacks, which were "Performed by a highly sophisticated actor," Ryan from Project Zero wrote in the first of a six-part blog series on their research.

In the case of the attacks that Google researchers uncovered, attackers executed the malicious code remotely on both the Windows and Android servers using Chrome exploits.

The exploits used against Windows included zero-day flaws, while Android users were targeted with exploit chains using known "n-day" exploits, though they acknowledge it's possible zero-day vulnerabilities could also have been used, researchers said.

The team spent months analyzing the attacks, including examining what happened post-exploitation on Android devices.

The researchers posted root-cause analyses for each of the four Windows zero-day vulnerabilities that they discovered being leveraged in their attacks.


News URL

https://threatpost.com/hacks-android-windows-zero-day/163007/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Android 4 0 17 2 0 19