Security News

BouldSpy Android Spyware: Iranian Government's Alleged Tool for Spying on Minority Groups
2023-05-02 11:56

A new Android surveillanceware possibly used by the Iranian government has been used to spy on over 300 individuals belonging to minority groups. "The spyware may also have been used in efforts to counter and monitor illegal trafficking activity related to arms, drugs, and alcohol," Lookout said, based on exfiltrated data that contained photos of drugs, firearms, and official documents issued by FARAJA. BouldSpy, like other Android malware families, abuses its access to Android's accessibility services and other intrusive permissions to harvest sensitive data such as web browser history, photos, contact lists, SMS logs, keystrokes, screenshots, clipboard content, microphone audio, and video call recordings.

Spyware slinger QuaDream’s reported demise may be the canary in the coal mine
2023-04-19 20:20

Analysis Israeli spyware shop QuaDream is reportedly shutting down due to financial troubles. The reported closure of the little-known nine-year-old company likely won't reduce the use of spyware - QuaDream's much higher profile and more infamous brethren, NSO Group, last year rolled out at least three new exploits targeting devices running versions 15 and 16 of Apple's iOS operating system.

Israeli Spyware Vendor QuaDream to Shut Down Following Citizen Lab and Microsoft Expose
2023-04-17 16:32

Israeli spyware vendor QuaDream is allegedly shutting down its operations in the coming days, less than a week after its hacking toolset was exposed by Citizen Lab and Microsoft. The company's board of directors are looking to sell off its intellectual property, the report further added.

Israel-based Spyware Firm QuaDream Targets High-Risk iPhones with Zero-Click Exploit
2023-04-12 11:58

It's also suspected that the company abused a zero-click exploit dubbed ENDOFDAYS in iOS 14 to deploy spyware as a zero-day in version 14.4 and 14.4.2. While QuaDream is not directly involved in targeting, it is known to sell its "Exploitation services and malware" to government customers, the tech giant assessed with high confidence.

Another zero-click Apple spyware maker just popped up on the radar again
2023-04-12 00:42

Reports from Microsoft and The University of Toronto's Citizen Lab both conclude that government-serving spyware maker QuaDream used a zero-click exploit targeting Apple devices running iOS 14 to deliver spyware marketed under the name Reign to victims' phones. Once somehow up and running via this method, the spyware was able to exfiltrate various elements of device, carrier, and network info; search for and retrieve files; use the camera in the background; monitor calls; access the iOS keychain; generate iCloud one-time passwords; and more, said Microsoft.

iPhones hacked via invisible calendar invites to drop QuaDream spyware
2023-04-11 17:46

Microsoft and Citizen Lab discovered commercial spyware made by an Israel-based company QuaDream used to compromise the iPhones of high-risk individuals using a zero-click exploit named ENDOFDAYS. The attackers targeted a zero-day vulnerability affecting iPhones running iOS 1.4 up to 14.4.2 between January 2021 and November 2021, using what Citizen Lab described as backdated and "Invisible iCloud calendar invitations." Compromised devices belonged to "At least five civil society victims of QuaDream's spyware and exploits in North America, Central Asia, Southeast Asia, Europe, and the Middle East," Citizen Lab researchers said.

Apple zero-day spyware patches extended to cover older Macs, iPhones and iPads
2023-04-10 20:20

Simply put, there were zero days during which even the most proactive and cybersecurity conscious users amongst us could have been patched in advance of the crooks. Just to be clear: the Apple Safari browser uses WebKit for "Processing web content" on all Apple devices, although third-party browsers such as Firefox, Edge and Chromium don't use WebKit on Mac.

Apple issues emergency patches for spyware-style 0-day exploits – update now!
2023-04-08 01:20

Apple's App Store rules mean that all browsers on iPhones and iPads must use WebKit, making this sort of bug a truly cross-browser problem for mobile Apple devices.Kernel code execution bugs are inevitably much more serious than app-level bugs, because the kernel is responsible for managing the security of the entire system, including what permissions apps can acquire, and how freely apps can share files and data between themselves.

S3 Ep129: When spyware arrives from someone you trust
2023-04-06 18:57

DOUG. Wi-Fi hacks, World Backup Day, and supply chain blunders. DUCK. Very simply put, the only backup you will ever regret is the one you did not make.

CISA orders agencies to patch bugs exploited to drop spyware
2023-03-30 19:52

The Cybersecurity and Infrastructure Security Agency has ordered federal agencies today to patch security vulnerabilities exploited as zero-days in recent attacks to install commercial spyware on mobile devices. One month later, a complex chain of multiple 0-days and n-days was exploited to target Samsung Android phones running up-to-date Samsung Internet Browser versions.