[ad_1]
Israeli spyware Owned by the developer NSO Group Shock Over the years, the global security community has Provocation and Effective Hacking tool It can target both Android and iOS devices. The company’s products have been abused by its customers around the world, so much so that the NSO Group is now facing sanctions, high-profile lawsuits and an uncertain future.But one New analysis The ForcedEntry iOS exploit of the spyware maker — deployed this year in many targeted attacks against militants, dissidents, and journalists — brought a more basic warning: private companies can produce the most elite The technical ingenuity and complexity of the hacker tool is a government-supported development group.
Google’s Project Zero bug-hunting team analyzed ForcedEntry using a sample provided by researchers at the Citizen Lab at the University of Toronto, which was provided by researchers at the Citizen Lab at the University of Toronto. Widely published Targeted attacks on exploiting vulnerabilities this year.Amnesty International researchers also Conducted important research About this year’s hacking tools. The vulnerability exploits zero-click or no-interaction attacks, which means that the victim does not need to click on the link or grant the hacker permission to move on. Project Zero discovered that ForcedEntry used a series of smart strategies to target Apple’s iMessage platform, bypassing the company’s increased protection measures in recent years, making such attacks more difficult, and cleverly taking over the device to install NSO’s flagship spyware implant物 Pegasus.
Apple released a series of patches in September and October to mitigate ForcedEntry attacks and strengthen iMessage to defend against similar attacks in the future. But the Zero Project researchers wrote in their analysis that ForcedEntry is still “one of the most technically complex vulnerabilities we have seen.” They said that the NSO Group has achieved a certain level of innovation and improvement, which is generally considered reserved for a small group of nation-state hackers.
“We have not seen a wild attack that builds equivalent functionality from such a limited starting point, it is impossible to interact with the attacker’s server, JavaScript or similar scripting engines are not loaded, etc.,” Ian Beer and Samuel Groß of Project Zero told WIRED wrote in an email. “Many people in the security community believe that this type of exploitation—single remote code execution—is a solved problem. They believe that the sheer weight of mitigation measures provided by mobile devices is essential for building a reliable single attack. Too high. This shows that not only is it possible, but it can be reliably used against humans in the wild.”
Apple Added iMessage protection Called BlastDoor in iOS 14 in 2020 Zero project research Regarding the threat of zero-click attacks. Beer and Groß stated that BlastDoor does seem to succeed in making non-interactive iMessage attacks more difficult to implement. They told Wired magazine: “Allowing attackers to work harder and take more risks is part of the plan to help make zero-day difficult.” But NSO Group finally found a way out.
ForcedEntry uses the weakness of iMessage to accept and interpret files such as GIFs to trick the platform into opening malicious PDFs, and the victim does nothing at all. The attack exploited a vulnerability in traditional compression tools used to process text in images from physical scanners, allowing NSO Group customers to completely take over the iPhone. Essentially, the algorithms used for photocopying and scanning compression in the 1990s are still lurking in modern communication software, with all the flaws and baggage.
[ad_2]
Source link






