Russian APT29 hackers use iOS, Chrome exploits created by spyware vendors
ID: 16f21483-173b-5f08-b335-7fec924dc14d
STIX ID: report--16f21483-173b-5f08-b335-7fec924dc14d
Feed Name: Bleeping Computer
APT29 ("Midnight Blizzard") executed watering-hole attacks on multiple Mongolian government websites between Nov 2023 and Jul 2024, leveraging iOS WebKit and chained Google Chrome zero-day/n-day exploits (notably CVE-2023-41993, CVE-2024-5274, CVE-2024-4671) to exfiltrate browser cookies, passwords and other sensitive data; the exploit code closely matched tools previously used by commercial spyware vendors (NSO Group, Intellexa), implying possible compromise, purchase, or insider leakage of those vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
