{"id":47099,"date":"2019-08-31T04:31:25","date_gmt":"2019-08-31T02:31:25","guid":{"rendered":"https:\/\/www.rudebaguette.com\/?p=47099"},"modified":"2019-08-31T04:31:36","modified_gmt":"2019-08-31T02:31:36","slug":"google-security-team-reveals-years-long-spyware-attack-on-iphone-users","status":"publish","type":"post","link":"https:\/\/www.rudebaguette.com\/en\/2019\/08\/google-security-team-reveals-years-long-spyware-attack-on-iphone-users\/","title":{"rendered":"Google security team reveals years-long spyware attack on iPhone users"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Security researchers at Google have discovered a hacking operation which installed malware on the iPhones of \u201cthousands of users a week,\u201d over two and a half years,\u00a0<a href=\"https:\/\/www.bbc.com\/news\/technology-49520355\" target=\"_blank\" rel=\"noopener\">according to BBC News.<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity experts are\u00a0<a href=\"https:\/\/www.latimes.com\/business\/story\/2019-08-30\/websites-infected-iphones-with-spyware-researchers-say\" target=\"_blank\" rel=\"noopener\">calling it the worst<\/a> general security failure yet found on Apple devices, and some researchers have suggested it showed signs of a hacking effort by a nation-state.\u00a0The vulnerability was discovered and patched earlier this year. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The malware installed \u2018monitoring implants\u2019 on the iPhones of users who visited a number of hacked websites. No further interaction was needed for the malware to breach the devices, and once installed, hackers were able to monitor contacts, location data, chat histories, images, messages, passwords, and other sensitive information. The implant was also able to access data from apps like Instagram, WhatsApp, Telegram, Gmail, and Hangouts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;There was no target discrimination,\u201d\u00a0<a href=\"https:\/\/gizmodo.com\/google-hackers-reveal-websites-hacked-thousands-of-ipho-1837743833\" target=\"_blank\" rel=\"noopener\">according to cybersecurity expert<\/a> Ian Beer, a member of Google\u2019s Project Zero security team. \u201cSimply visiting the hacked site was enough for the exploit server to attack your device, and if it was successful, install a monitoring implant.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Beer\u00a0<a href=\"https:\/\/googleprojectzero.blogspot.com\/2019\/08\/a-very-deep-dive-into-ios-exploit.html\" target=\"_blank\" rel=\"noopener\">described the attack in a blog post<\/a> Thursday.\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Project Zero has become controversial in the tech world\u2014when the team\u2019s white-hat hackers find vulnerabilities, they announce their findings to the public 90 days after reporting them to the company involved, regardless of whether the bug has been fixed,\u00a0<a href=\"https:\/\/www.theguardian.com\/technology\/2019\/aug\/30\/hackers-monitoring-implants-iphones-google-says\" target=\"_blank\" rel=\"noopener\">according to\u00a0<em>The Guardian.<\/em><\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Apple was notified of the vulnerabilities in February, and released a patch within a week. At the time, they told users the update included \u201cimproved input validation\u201d to fix \u201cmemory corruption\u201d issues.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The implant was not persistent, which meant a simple restart of the device could clear it from memory. But once their data was acquired, this may not have protected users, according to Beer.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cGiven the breadth of information stolen, the attackers may nevertheless be able to maintain persistent access to various accounts and services by using the stolen authentication tokens from the keychain, even after they lose access to the device.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Current iPhone users should ensure that their software is updated to the most recent version. But Beer points out that for every hacking effort that gets discovered, there are many more that haven\u2019t been uncovered.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAll that users can do is be conscious of the fact that mass exploitation still exists and behave accordingly; treating their mobile devices as both integral to their modern lives, yet also as devices which when compromised, can upload their every action into a database to potentially be used against them.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Photo by&nbsp;<a href=\"https:\/\/pixabay.com\/users\/helloolly-371803\/?utm_source=link-attribution&amp;utm_medium=referral&amp;utm_campaign=image&amp;utm_content=518101\" target=\"_blank\" rel=\"noopener\">Olly Browning<\/a>&nbsp;from&nbsp;<a href=\"https:\/\/pixabay.com\/?utm_source=link-attribution&amp;utm_medium=referral&amp;utm_campaign=image&amp;utm_content=518101\" target=\"_blank\" rel=\"noopener\">Pixabay<\/a>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers at Google have discovered a hacking operation which installed malware on the iPhones of \u201cthousands of users a week,\u201d over two and a half years,\u00a0according to BBC News. Cybersecurity experts are\u00a0calling it the worst general security failure yet found on Apple devices, and some researchers have suggested it showed signs of a hacking<\/p>\n","protected":false},"author":77,"featured_media":47100,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"subtitle":"","footnotes":""},"categories":[113],"tags":[84,885,129,91,10214],"class_list":["post-47099","post","type-post","status-publish","format-standard","has-post-thumbnail","category-finance","tag-apple","tag-cybersecurity","tag-google","tag-iphone","tag-user-data"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/posts\/47099","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/users\/77"}],"replies":[{"embeddable":true,"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/comments?post=47099"}],"version-history":[{"count":0,"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/posts\/47099\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/media\/47100"}],"wp:attachment":[{"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/media?parent=47099"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/categories?post=47099"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.rudebaguette.com\/en\/wp-json\/wp\/v2\/tags?post=47099"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}