logo

Spyware vendors use 0-days and n-days against popular platforms

ID: f6c78b37-eee0-5db3-bc4f-9b8efd86b752

STIX ID: report--f6c78b37-eee0-5db3-bc4f-9b8efd86b752

Feed Name: Google's Threat Analysis Group (TAG)

Threat Score
90/100

Date Published: 2023-03-29

Date Updated: 2026-04-27

Author: Clement Lecigne

...
...

Google TAG uncovered a December 2022 multi-stage exploit chain delivered via one-time SMS links to UAE users that abused multiple 0-day and n-day vulnerabilities in Samsung Internet Browser (Chromium 102) and device components to install a full-featured C++ Android spyware suite; the report lists exploited CVEs (e.g., CVE-2022-4262, CVE-2022-3038, CVE-2022-22706, CVE-2023-0266), suggests ties to commercial spyware vendor Variston, and provides related IOCs and Android system/file indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.