Skip to main content

Apple Issues Emergency Fix for NSO Zero-Click Zero Day

 



Apple users should immediately update all their devices — iPhones, iPads, Macs and Apple Watches — to install an emergency patch for a zero-click zero-day exploited by NSO Group to install spyware.

The security updates, pushed out by Apple on Monday, include iOS 14.8 for iPhones and iPads, as well as new updates for Apple Watch and macOS. The patches will fix at least one vulnerability that the tech behemoth said “may have been actively exploited.”

Citizen Lab first discovered the never-before-seen, zero-click exploit, which it detected targeting iMessaging, last month. It’s allegedly been used to illegally spy on Bahraini activists with NSO Group’s Pegasus spyware, according to the cybersecurity watchdog.

The digital researchers dubbed the new iMessaging exploit ForcedEntry.

Citizen Group said in August that they had identified nine Bahraini activists whose iPhones were inflicted with Pegasus spyware between June 2020 and February 2021. Some of the activists’ phones suffered zero-click iMessage attacks that, besides ForcedEntry, also included the 2020 KISMET exploit.

The activists included three members of Waad (a secular Bahraini political society), three members of the Bahrain Center for Human Rights, two exiled Bahraini dissidents, and one member of Al Wefaq (a Shiite Bahraini political society), Citizen Lab wrote.

The ForcedEntry exploit was particularly notable in that it was successfully deployed against the latest iOS versions — 14.4 & 14.6 — blowing past Apple’s new BlastDoor sandboxing feature to install spyware on the iPhones of the Bahraini activists.

Citizen Lab first observed NSO Group deploying ForcedEntry in February 2021. Apple had just introduced BlastDoor, a structural improvement in iOS 14 meant to block message-based, zero-click exploits like these NSO Group-associated attacks — the month before. BlastDoor was supposed to prevent this type of Pegasus attack by acting as what Google Project Zero’s Samuel Groß called a “tightly sandboxed” service responsible for “almost all” of the parsing of untrusted data in iMessages.

In a post on Monday, Citizen Lab researchers said that in March 2021, they had examined the phone of a Saudi activist who requested anonymity and determined that the phone had been infected with NSO Group’s Pegasus spyware. Last Tuesday, Sept. 7, Citizen Lab forwarded artifacts from two types of crashes on another phone that had been infected with Pegasus, suspecting that both infections showed parts of the ForcedEntry exploit chain.

Citizen Lab forwarded the artifacts to Apple on Tuesday, Sept. 7. On Monday, Sept. 13, Apple confirmed that the files included a zero-day exploit against iOS and MacOS. Apple has designated the ForcedEntry exploit CVE-2021–30860: an as-yet-unrated flaw that Apple describes as “processing a maliciously crafted PDF may lead to arbitrary code execution.”

Sniffing out NSO Group’s Tracks


Citizen Lab described several distinct elements that gives researchers high confidence that the exploit can be tied to the secretive Israeli spyware maker NSO Group, including a forensic artifact called CascadeFail.

CascadeFail is a bug whereby “evidence is incompletely deleted from the phone’s DataUsage.sqlite file,” according to Citizen Lab. In CascadeFail, “an entry from the file’s ZPROCESS table is deleted, but not entries in the ZLIVEUSAGE table that refer to the deleted ZPROCESS entry,” they described.

That has NSO Group’s fingerprints, they said: “We have only ever seen this type of incomplete deletion associated with NSO Group’s Pegasus spyware, and we believe that the bug is distinctive enough to point back to NSO.”

Another telltale sign: multiple process names installed by the ForcedEntry exploit, including the name “setframed”. That process name was used in an attack with NSO Group’s Pegasus spyware on an Al Jazeera journalist in July 2020, according to Citizen Lab: a detail that the watchdog didn’t reveal at the time.

Zero click remote exploits such as the novel method used by Pegasus spyware to invisibly infect an Apple device without the victim’s knowledge or the need for the victim to click on anything at all were used to infect one victim for as long as six months. They’re pure gold to governments, mercenaries and criminals who want to secretly surveil targets’ devices without being detected.

Pegasus is a powerful spyware: it can turn on a target’s camera and microphone so as to record messages, texts, emails, and calls, even if they’re sent via encrypted messaging apps such as Signal.

Pegasus’s Threadbare Narrative


NSO has long maintained that it only sells its spyware to a handful of intelligence communities within countries that have been thoroughly vetted for human rights violations. The company has repeatedly tried to keep up that narrative, taking the tactic of questioning Citizen Lab’s methods and motives.

But, as pointed out by Hank Schless, Senior Manager of security solutions at endpoint-to-cloud security company Lookout, the narrative is now pretty threadbare. “The recent exposure of 50,000 phone numbers linked to targets of NSO Group customers was all people needed to see right through what NSO claims,” he told Threatpost on Monday.

“Since Lookout and The Citizen Lab first discovered Pegasus back in 2016, it has continued to evolve and take on new capabilities,” he elaborated. “It can now be deployed as a zero-click exploit, which means that the target user doesn’t even have to tap a malicious link for the surveillanceware to be installed.

While the malware has adjusted its delivery methods, the basic exploit chain remains the same, Schless continued. “Pegasus is delivered via a malicious link that’s been socially engineered to the target, the vulnerability is exploited and the device is compromised, then the malware communicated back to a command-and-control (C2) server that gives the attacker free reign over the device. Many apps will automatically create a preview or cache of links in order to improve the user experience. Pegasus takes advantage of this functionality to silently infect the device.”

Schless said that this is an example of how important it is for both individuals and enterprise organizations to have visibility into the risks their mobile devices present, Pegasus being just onei “extreme, but easily understandable example.

“There are countless pieces of malware out there that can easily exploit known device and software vulnerabilities to gain access to your most sensitive data,” he continued. “From an enterprise perspective, leaving mobile devices out of the greater security strategy can represent a major gap in the ability to protect the entire infrastructure from malicious actors. Once the attacker has control of a mobile device or even compromises the user’s credentials, they have free access to your entire infrastructure. Once they enter your cloud or on-prem apps, they can move laterally and identify sensitive assets to encrypt for a ransomware attack or exfiltrate to sell to the highest bidder.”

Kevin Dunne, president at unified access orchestration provider Pathlock, noted that the Pegasus infections point to the need for businesses to look beyond securing servers and workstations as primary targets for cyberattacks and espionage. “Mobile devices are now used broadly and contain sensitive information that needs to be protected,” he explained.

To protect themselves against spyware, businesses should look at their mobile device security strategy, Dunne said — particularly when threats come in forms that are far more insidious than suspicious SMS messages or phishy links that security teams can train users to avoid.

“Spyware attackers have now engineered zero click attacks which are able to get full access to a phone’s data and microphone/camera by using vulnerabilities in third party apps or even built-in applications,” Dunne said. “Organizations need to make sure they have control over what applications users download on to their phones, and can ensure they are up to date so any vulnerabilities are patched.”

Originally published at https://threatpost.com 

Comments

Popular posts from this blog

[Update] Twitter down, not working on Android | How to fix Twitter crashing issue | DigiStatement

In our earlier posts, we reported that a lot of users are posting about the crashing issue with the Twitter app on the Android platform. Some users posted that the app is not opening after updating it to the latest version on Google Play Store, while some reported that they are using the older version of the Twitter app and still facing the crashing issue. Well, Twitter officially acknowledged the issues with the Android app of Twitter and posted an update with the official account of Twitter Support. In the tweet, Twitter also suggested its users to not update and download the latest version of the app. You can check out the official tweet below. How to fix Twitter crashing issue - If you are still using the older version of the Twitter app, first you need to turn off the auto-update feature in the Google Play Store. For this, go to the Play Store app then head to Settings > Auto-Update Apps > Don’t Auto-Update Apps . You can enable this feature later, as it will s...

Scraped data of 500 million LinkedIn users being sold online, 2 million records leaked as proof | CyberNews

  Updated on 07/04: We updated our personal data leak checker database with more than 780,000 email addresses associated with this leak . Use it to find out if your LinkedIn profile has been scraped by the threat actors. Days after a massive Facebook data leak made the headlines, it seems like we’re in for another one, this time involving LinkedIn. An archive containing data purportedly scraped from 500 million LinkedIn profiles has been put for sale on a popular hacker forum, with another 2 million records leaked as a proof-of-concept sample by the post author. The four leaked files contain information about the LinkedIn users whose data has been allegedly scraped by the threat actor, including their full names, email addresses, phone numbers, workplace information, and more. To see if your email address has been exposed in this data leak or other security breaches, use our personal data leak checker with a library of 15+ billion breached records . While users on the hacker foru...

Facebook bows to Singapore's 'fake news' law

Facebook has added a correction notice to a post that Singapore’s government said contained false information. It is the first time Facebook has issued such a notice under the city-state’s controversial “fake news” law. Singapore claimed the post, by fringe news site States Times Review (STR), contained “scurrilous accusations”. The note issued by the social media giant said it “is legally required to tell you that the Singapore government says this post has false information”. Facebook’s addition was embedded at the bottom of the original post, which was not altered. It was only visible to social media users in Singapore. Singapore passes controversial fake news law Concern over Singapore’s anti-fake news law Singapore: What you need to know In an emailed statement to the BBC, Facebook said it had applied a label to a post “determined by the Singapore government to contain false information”, as required under the “fake news” law. The company — which has its Asia ...