logo

State-backed attackers and commercial surveillance vendors repeatedly use the same exploits

ID: 91fbee0b-a500-533f-b093-e0a0d16c1cd6

STIX ID: report--91fbee0b-a500-533f-b093-e0a0d16c1cd6

Feed Name: Google's Threat Analysis Group (TAG)

Threat Score
85/100

Date Published: 2024-08-29

Date Updated: 2026-04-27

Author: Clement Lecigne

...
...

This report describes a sophisticated targeted watering‑hole campaign (observed July 2024) that delivered exploit chains against iOS and Chrome to bypass platform protections and exfiltrate authentication cookies and device information from high‑value sites (Google, Microsoft, LinkedIn, iCloud, etc.). The iOS payload reuses a cookie‑stealer framework linked to previous government‑backed activity and uses JIT/PAC bypasses, while the Chrome chain includes a sandbox escape and ECDH key exchange for staged payload delivery.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.