Google: How we tackled this iPhone, Android spyware
- Reference: 1656067569
- News link: https://www.theregister.co.uk/2022/06/24/spyware_iphones_android_isp/
- Source link:
RCS Labs customers include law-enforcement agencies worldwide, according to the vendor's website. It's one of more than 30 outfits Google researchers are tracking that sell exploits or surveillance capabilities to government-backed groups. And we're told this particular spyware runs on both iOS and Android phones.
We understand this particular campaign of espionage involving RCS's spyware was [1]documented last week by Lookout, which dubbed the toolkit "Hermit." We're told it is potentially capable of spying on the victims' chat apps, camera and microphone, contacts book and calendars, browser, and clipboard, and beam that info back to base. It's said that Italian authorities have used this tool in tackling corruption cases, and the Kazakh government has had its hands on it, too.
[2]
On Thursday this week, TAG revealed its analysis of the software, and how it helped dismantle the infection.
[3]
[4]
According to Googlers Benoit Sevens and Clement Lecigne, some targets were sent text messages asking them to install an application to fix their mobile data connectivity. This app in fact infected the device with RCS's spyware. It appears the snoops using the surveillance tool got the victims' cellular providers to degrade their wireless internet connectivity, thus convincing the marks to run the app.
"We believe this is the reason why most of the applications masqueraded as mobile carrier applications," Sevens and Lecigne [5]explained .
[6]
In cases without any telco help, the spies sent a link to a page offering malicious applications masquerading as legit messaging apps from Facebook parent Meta. Running these programs infected the device with spyware.
Getting the app to download and run on iOS needed some extra steps due to the security measures in the operating system: for one thing, the app wasn't coming from the official App Store and thus would normally be rejected. The snoops instead followed Apple's notes on how to [7]distribute proprietary in-house apps to iThings, according to the Google bug hunters.
This allowed the miscreants to produce an app digitally signed by a company enrolled in the Apple Developer Enterprise Program, and crucially, one that could be installed on a victim's device by getting them to fetch and run it from a webpage.
[8]
The iPhone app itself contains multiple parts, including a privilege-escalation exploit to escape from the sandbox in which it is run, along with an agent that can steal files from iOS devices. In their analysis, Sevens and Lecigne analyzed an app with exploit code for the following vulnerabilities:
[9]CVE-2018-4344 internally referred to and publicly known as LightSpeed.
[10]CVE-2019-8605 internally referred to as SockPort2 and publicly known as SockPuppet
[11]CVE-2020-3837 internally referred to and publicly known as TimeWaste.
[12]CVE-2020-9907 internally referred to as AveCesare.
[13]CVE-2021-30883 internally referred to as Clicked2, [14]marked as being exploited in-the-wild by Apple in October 2021.
[15]CVE-2021-30983 internally referred to as Clicked3, [16]fixed by Apple in December 2021.
The security researchers said [17]CVE-2021-30883 and [18]CVE-2021-30983 were zero-day exploits, and Project Zero [19]published a technical analysis of the latter.
Android deployment
Meanwhile, on Android, the installation process worked like this: first, the victim is sent a link to a webpage that tricks them into fetching and installing a malicious app that looks like a legitimate Samsung application that, when launched, opens a [20]webview that displays a legitimate website related to the icon.
Once installed, it requests permissions, uses messaging services such as Firebase Cloud Messaging and Huawei Messaging Service for command-and-control communications, and then gets on with the business of espionage and data theft.
It may be able to download additional malware as well, the researchers warn. "While the APK itself does not contain any exploits, the code hints at the presence of exploits that could be downloaded and executed," Sevens and Lecigne wrote.
They also listed several hashes of excecutables, domains used to distribute the code, and command-and-control domains and IP addresses the presence of which in logs could indicate a compromised device.
[21]Predator spyware sold with Chrome, Android zero-day exploits to monitor targets
[22]Google tracked record 58 exploited-in-the-wild zero-day security holes in 2021
[23]India's ongoing outrage over Pegasus malware tells a bigger story about privacy law problems
[24]Watch out for phishing emails that inject spyware trio
Google notified all of the known Android victims, made changes in Google Play Protect to block the RCS code from running, and disabled the Firebase project used for command-and-control communications, we're told. That should hopefully pull the plug on it for now.
"This campaign is a good reminder that attackers do not always use exploits to achieve the permissions they need," Sevens and Lecigne added. "Basic infection vectors and drive-by downloads still work and can be very efficient with the help from local ISPs." ®
Get our [25]Tech Resources
[1] https://www.lookout.com/blog/hermit-spyware-discovery
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YrXfokTm4wbMz7kZdUFFCgAAANY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrXfokTm4wbMz7kZdUFFCgAAANY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrXfokTm4wbMz7kZdUFFCgAAANY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YrXfokTm4wbMz7kZdUFFCgAAANY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://support.apple.com/en-bw/guide/deployment/depce7cefc4d/web
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/research&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YrXfokTm4wbMz7kZdUFFCgAAANY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-4344
[10] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8605
[11] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-3837
[12] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9907
[13] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30883
[14] https://support.apple.com/en-us/HT212846
[15] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30983
[16] https://support.apple.com/en-us/HT212976
[17] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30883
[18] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30983
[19] https://googleprojectzero.blogspot.com/2022/06/curious-case-carrier-app.html
[20] https://developer.android.com/reference/android/webkit/WebView
[21] https://www.theregister.com/2022/05/24/predator_spyware_zero_days/
[22] https://www.theregister.com/2022/04/20/google_zero_days/
[23] https://www.theregister.com/2022/05/08/pegasus_india_data_law_controversy/
[24] https://www.theregister.com/2022/06/01/phishing-rat-bitrat-fortinet/
[25] https://whitepapers.theregister.com/
Re: Google's Threat Analysis Group
It looks they are doing nothing to stop NSO Pegasus as they did with this one....
Re: Google's Threat Analysis Group
Spy Vs. Spy... Google good, others bad.
> It appears the snoops using the surveillance tool got the victims' cellular providers to degrade their wireless internet connectivity, thus convincing the marks to run the app.
Which Italian cellular provider?
TIM?
Vodafone?
Three?
Any provider that willingly goes along with such a scheme ought to be blacklisted (and publicly shamed).
On both sides of the ocean.
Why? They do have already to comply with tap warrants. This is not much different. Doing it under the proper legal framework help to jail criminals. Otherwise it becomes authoritarian surveillance. Just like FISA or CLOUD Act.
Having used TIM, how would you know their service had degraded?
Google's thoughts
I suspect Google saw this and thought "They're stealing our data." rather than "They're stealing the user's data."
Re: Google's thoughts
I doubt the app prevented the host OS from grabbing all the data it usually grabs.
That might be an easy way onto devices belonging to slightly more tech-savvy users though: "Did you know Google records everything you do on Android and listens to you even when you're not using your phone? Download and install [1]this app now to stop it!"
[1] https://www.youtube.com/watch?v=dQw4w9WgXcQ
Re: Google's thoughts
" I doubt the app prevented the host OS from grabbing all the data it usually grabs "
Correct of course, but it's still competition and 'we can't allow that'.
Watching people's every move and collecting their info – not on our watch, says web ads giant
Yeah right!
Would sound a tiny bit more convincing if Google weren't all about that shit themselves, eh?
You just needed to add a "Someone else" to the start of your byline and you'd've been good.
Bit confused as to whether this was being used as a law enforcement tool (as per the Italian usage description) or for nefarious means by a.n.other in eastern Europe ... sounds like a government installation which could be either use but the story seems to document an exploit method rather than a reason for exploitation. If it was used for "legitimate purposes" of law enforcement why is Google documenting it? If not, why are they not naming names and detailing reasons for the exploit?
Like NSO groups illegal spyware this is an exploit allowing the installation of spyware against the user's wishes and bypassing OS level protections. This is illegal spyware no matter how it is being used.
It's not different than implanting a bug to track and listen to criminals - which is usually done against the criminal wishes, and usually trespassing into private properties. Just, done under a warrant, it is legal.
"why is Google documenting it"
Because stomping on Italian feet is far less dangerous than stomping on Israeli ones... it makes Google look good and people forget they let others do the same....
Google's Threat Analysis Group
Does it monitor and track for USA regime-backed spyware? Yes or no?