iTnews
  • Home
  • News
  • Technology
  • Security

Suspected gov hackers behind 'watering hole' attacks in Hong Kong

By Juha Saarinen on Nov 12, 2021 3:00PM
Suspected gov hackers behind 'watering hole' attacks in Hong Kong

Well-resourced group drops payload with quality code.

Google's Threat Analysis Group (TAG) has discovered "watering hole" attacks with malware deployed onto Hong Kong websites, including a media outlet and a prominent pro-democracy and political group.

The malware was found in August this year and TAG found a root superuser privilege escalation exploit for the macOS Catalina operating system XNU kernel, which would attempt to download and install a backdoor on targets' computers.

Only Intel-based Macs running macOS Catalina were served a full exploit chain; later macOS versions such as Big Sur caused the exploit to crash due to Apple's generic security protections.

The code for the exploit is advanced, and highly obfuscated to make analysis more difficult.

"We believe this threat actor to be a well-resourced group, likely state backed, with access to their own software engineering team based on the quality of the payload code," Erye Hernandez from Google TAG wrote.

Google TAG did not directly attribute the attacks to a particular country or hacking group.

TAG said Apple's mobile iOS operating system was also targeted by the attackers, using the Ironsquirrel framework to deliver encrypted exploits to victims' browsers, a different tactic compared to macOS.

However, TAG was not able to capture a complete iOS exploit chain, only a partial one in which a bug from 2019 was used for remote code execution in the Safari web browser.

Among the features in the backdoor were victim device fingerprinting, screen capture, file transfers, terminal command execution, audio recording and keystroke logging.

Apple patched the vulnerability in September this year.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
applegooglehong kongmicrosoftsecuritytagthreat analysis group

Partner Content

Security "mindset shift" needed to protect organisations
Promoted Content Security "mindset shift" needed to protect organisations
The Great Resignation has intensified insider security threats
Promoted Content The Great Resignation has intensified insider security threats
"We're seeing some good policy put in place, but that's the exception"
Partner Content "We're seeing some good policy put in place, but that's the exception"
Security: Understanding the fundamentals of governance, risk & compliance
Promoted Content Security: Understanding the fundamentals of governance, risk & compliance

Sponsored Whitepapers

Extracting the value of data using Unified Observability
Extracting the value of data using Unified Observability
Planning before the breach: You can’t protect what you can’t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership

Events

  • Micro Focus Information Management & Governance (IM&G) Forum 2022
  • CRN Channel Meets: CyberSecurity Live Event
  • IoT Insights: Secure By Design for manufacturing
  • Cyber Security for Government Summit
By Juha Saarinen
Nov 12 2021
3:00PM
0 Comments

Related Articles

  • Threat actors worked with ISPs to plant malware from Italian spyware vendor
  • Edtech vendors invaded student privacy: Human Rights Watch
  • F5 BIG-IP systems vulnerable to remote takeover
  • Tech giants face supervisory fee under new EU rules
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Qantas calls time on IBM, Fujitsu in tech modernisation

Qantas calls time on IBM, Fujitsu in tech modernisation

Service NSW hits digital services goal two years early

Service NSW hits digital services goal two years early

NBN Co taking orders for 'non-premises' connections

NBN Co taking orders for 'non-premises' connections

NSW Police scores $100m to connect body-cams to firearms, tasers

NSW Police scores $100m to connect body-cams to firearms, tasers

Digital Nation

COVER STORY: Operationalising net zero through the power of IoT
COVER STORY: Operationalising net zero through the power of IoT
Integrity, ethics and board decisions in the digital age
Integrity, ethics and board decisions in the digital age
The security threat of quantum computing
The security threat of quantum computing
IBM global chief data officer on the rise of the number crunchers
IBM global chief data officer on the rise of the number crunchers
Crypto experts optimistic about future of Bitcoin: Block
Crypto experts optimistic about future of Bitcoin: Block
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.