Skip to main content

Google says attackers worked with ISPs to deploy Hermit spyware on Android and iOS

Illustration by Alex Castro / The Verge

A sophisticated spyware campaign is getting the help of internet service providers (ISPs) to trick users into downloading malicious apps, according to research published by Google’s Threat Analysis Group (TAG) (via TechCrunch). This corroborates earlier findings from security research group Lookout, which has linked the spyware, dubbed Hermit, to Italian spyware vendor RCS Labs.

Lookout says RCS Labs is in the same line of work as NSO Group — the infamous surveillance-for-hire company behind the Pegasus spyware — and peddles commercial spyware to various government agencies. Researchers at Lookout believe Hermit has already been deployed by the government of Kazakhstan and Italian authorities. In line with these findings, Google has identified victims in both countries and says it will notify affected users.

As described in Lookout’s report, Hermit is a modular threat that can download additional capabilities from a command and control (C2) server. This allows the spyware to access the call records, location, photos, and text messages on a victim’s device. Hermit’s also able to record audio, make and intercept phone calls, as well as root to an Android device, which gives it full control over its core operating system.

The spyware can infect both Android and iPhones by disguising itself as a legitimate source, typically taking on the form of a mobile carrier or messaging app. Google’s cybersecurity researchers found that some attackers actually worked with ISPs to switch off a victim’s mobile data to further their scheme. Bad actors would then pose as a victim’s mobile carrier over SMS and trick users into believing that a malicious app download will restore their internet connectivity. If attackers were unable to work with an ISP, Google says they posed as seemingly authentic messaging apps that they deceived users into downloading.

Researchers from Lookout and TAG say apps containing Hermit were never made available via the Google Play or Apple App Store. However, attackers were able to distribute infected apps on iOS by enrolling in Apple’s Developer Enterprise Program. This allowed bad actors to bypass the App Store’s standard vetting process and obtain a certificate that “satisfies all of the iOS code signing requirements on any iOS devices.”

Apple told The Verge that it has since revoked any accounts or certificates associated with the threat. In addition to notifying affected users, Google has also pushed a Google Play Protect update to all users.



Source: The Verge

Popular posts from this blog

Keep your Oculus Quest controllers going strong with these batteries

The Touch Controllers for the Oculus Quest 2 ship with one disposable AA battery each, but once those run out of juice, you should invest in the best Oculus Quest 2 replacement batteries to fill in for them. While the Touch Controllers last much longer than the headset's limited battery, it's still wise to invest in some rechargeable batteries or a stack of disposable batteries to stop your VR sessions from getting disrupted. Here are the batteries and chargers we recommend for your Oculus Touch controllers. Best rechargable batteries + charger Panasonic K-KJ55MCA4BA 3 Hour Quick Charger with 4 AA eneloop Rechargeable Batteries Staff Pick These rechargeable batteries store up to 2,000 mAh of power and can be recharged up to 2,100 times. They can be charged completely from dead or partially charged without damaging the energy storage memory. We recommend buying them with the quick charger accessory, which will get your AAs recharged in no time, but you can also purchas

Uber Eats exits seven markets, transfers one as part of competitive retooling

Uber Eats is pulling out of a clutch of markets — shuttering its on-demand food offering in the Czech Republic, Egypt, Honduras, Romania, Saudi Arabia, Uruguay and Ukraine. It’s also transferring its Uber Eats business operations in the United Arab Emirates (UAE) to Careem, its wholly owned ride-hailing subsidiary that’s mostly focused on the Middle East. “Consumers and restaurants using the Uber Eats app in the UAE will be transitioned to the Careem platform in the coming weeks, after which the Uber Eats app will no longer be available,” it writes in a regulatory filing detailing the operational shifts. “These decisions were made as part of the Company’s ongoing strategy to be in first or second position in all Eats markets by leaning into investment in some countries while exiting others,” the filing adds. An Uber spokesman said the changes are not related to the coronavirus pandemic but rather related to an ongoing “strategy of record” for the company to hold a first or s

This popular open-source web server has some serious security flaws

OpenLiteSpeed Web Server, a globally popular open-source web server , was carrying a couple of high-severity vulnerabilities, experts have warned. Threat actors that managed to exploit these flaws would have been given full privilege remote code execution capabilities, noted researchers from Unit 42, Palo Alto Networks’ cybersecurity research arm.  The team found OpenLiteSpeed Web Server carried three high-severity vulnerabilities, namely CVE-2022-0073 (an 8.8 severity score, high-severity remote code execution flaw), CVE-2022-0074 (an 8.8 high-severity privilege escalation flaw), and CVE-2022-0072 (a 5.8, medium-severity directory traversal flaw). The vulnerabilities also affected the enterprise version, LiteSpeed Web Server. Patch ready Unit 42 has notified LiteSpeed Technologies of its findings which has, subsequently, patched the flaws, and released new versions of the server, urging users to update their software immediately.  Organizations using OpenLiteSpeed versions 1.5.1

These Android games support Bluetooth controllers and they're better for it

Gaming is simply better with a controller in your hands. Gaming on Android typically requires you to settle for using touchscreen controls. However, some gracious game developers take the time and effort to add support for Bluetooth gamepads— and we love them for it. Since so few games provide this feature, we've taken the time to test and compiled our list of the best games that let you play with the best Bluetooth controller in your hands. We'd also recommend getting a Style Ring or PopSocket which can help prop your phone up at a good angle for gaming. You might recognize some of these games from the best Android games roundup and for good reason. But you're here for the best games with controller support, after all, so here I present to you the best you can find on the Play Store. The games Call of Duty Mobile GRID Autosport Tesla vs Lovecraft Evoland 2 Horizon Chase World Tour Riptide GP: Renegade Modern Combat 5: Blackout GTA: San Andreas Oceanhor