logo

Russian APT29 hackers use iOS, Chrome exploits created by spyware vendors

ID: 16f21483-173b-5f08-b335-7fec924dc14d

STIX ID: report--16f21483-173b-5f08-b335-7fec924dc14d

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-08-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

APT29 ("Midnight Blizzard") executed watering-hole attacks on multiple Mongolian government websites between Nov 2023 and Jul 2024, leveraging iOS WebKit and chained Google Chrome zero-day/n-day exploits (notably CVE-2023-41993, CVE-2024-5274, CVE-2024-4671) to exfiltrate browser cookies, passwords and other sensitive data; the exploit code closely matched tools previously used by commercial spyware vendors (NSO Group, Intellexa), implying possible compromise, purchase, or insider leakage of those vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.