Live data from Hacker News

Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

citizenlab.ca

191–200 of 314 posts

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#191
> regularhours.net and holdmydoor.com appeared on a Turkish CERT list in November 2019

> we observed MONARCHY and SNEAKY KESTREL continue to use these domain names in attacks through August 2020.

Interesting to see that the malicious hosts are not in any standard blacklist or safe browsing databases for browsers while Turkey's CERT has been sink-holing them via ISPs on a national level since at least 2019.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#192

As someone that isn't a developer, I wonder how many zero days come from people inside the software team. To simply have knowledge of a difficult bug that hasn't been resolved would seem to be valuable commodity in a closed source system.

I don't think this is a thing for two reasons :

* firstly, not many people outside the security world knows that bugs are a valuable commodity for attackers. Same thing with internal orgs diagrams which are something you can sell to economic intelligence firms.

* secondly, top-tier orgs like FAANG usually peppers a lot of telemetry around known bugs in production code in order to see if someone isn't exploiting them (or simply to better track down the root cause).

That being said, attackers are reaaaaaally interested in getting access to internal bug trackers : https://grahamcluley.com/microsoft-bug-tracking-hack/

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#193
post #85

Earlier quoted context omitted.

Google has a very good internal security research team and there hasn't been a high impact/zero click RCE on androids that Google themselves maintain for a while. Considering the recent iOS exploits, you're likely to be a little bit safer on a Google phone and common sense at the moment - but I'm 100% sure that a player like NSO will have an exploit for your phone as well. Might have more luck with a dedicated "locke…

Apple's security architecture is leagues ahead of Android's. They have bespoke innovative protections at the hardware and hypervisor level, as well as an actual security CPU (as opposed to TrustZone on Androids, which is always swiss cheese in one way or another). This is largely possible because Apple are building their own silicon (none of the other silicon vendors are anywhere near as competent in this field). I s…

Android dominates the mobile OS market share though. Seems like targeting it would yield a higher ROI. Much like how malware writers target Windows, because it dominates the desktop OS market share.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#194
post #182

Earlier quoted context omitted.

>human rights activists will die Most Israelis I talked to (about this specific subject; including the ones, working for NSO Group) do not understand the concept of human rights. First two questions I get are "How gives these rights?" and "Where does the list written?" in this order with the same intonation. My guess it is result of some kind of indoctrination during high school and army service. P.S. I'm israeli

That's absolutely bullshit, many tech literate people here are against the weapon industry, which NSO is part of. Enough of them don't give a shit, which is why NSO can hire people from the intelligence arm of the army for ridiculous salaries.

I'm firmly in the camp that my brain will never be used in the weapons (or gambling) industry - no matter what the salary.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#195
post #61

More generally, is there a known correlation between kernel panics and exploits, especially on macOS? > Almisshal’s device shows what appears to be an unusual number of kernel panics (phone crashes) between January and July 2020. While some of the panics may be benign, they may also indicate earlier attempts to exploit vulnerabilities against his device.

Failed exploits, especially kernel-level ones, will result in higher system instability. I'm aware of at least one company (ZecOps) that specializes in detecting exploitations using crash analysis.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#196
post #61

More generally, is there a known correlation between kernel panics and exploits, especially on macOS? > Almisshal’s device shows what appears to be an unusual number of kernel panics (phone crashes) between January and July 2020. While some of the panics may be benign, they may also indicate earlier attempts to exploit vulnerabilities against his device.

I doubt it's macOS only, if you remember EternalBlue, that was called that way because it kept bluescreening on machines the NSA tested it on ...

The name came from a previous exploit called BlueKeep, which wasn't related to BSOD.

In fact: "On 6 September 2019, an exploit of the wormable BlueKeep security vulnerability was announced to have been released into the public realm.[4] The initial version of this exploit was, however, unreliable, being known to cause "blue screen of death" (BSOD) errors. A fix was later announced, removing the cause of the BSOD error."

They even fixed a BSOD issue that popped up in BlueKeep as that was no good to them.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#197
post #181
post #178

Earlier quoted context omitted.

The Israeli government has absolutely no say in how any of this plays out, that is the entire point of an independent judiciary. The lawsuit and sanctions are decided by the courts based on existing laws and precedent, and for them Facebook's size or position in the Israeli market does not (and should not) hold any weight whatsoever. The most the legislative can do is amend the relevant laws to make what Facebook tri…

Facebook could choose to leave the Israeli market so it would not be bound by Israeli law.

Yes, Facebook could do that. There's probably many laws in many other countries Facebook operates in that are a lot less reasonable than this one, but I guess if for some reason this was the specific hill they wanted to die on, they would absolutely be free to do so.

Facebook also has a pretty big engineering office in Tel-Aviv, which they'd probably have to close in this scenario. I imagine that would also be a massive PITA. But, again, there's nothing technically stopping them from doing that.

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#198

> We were unable to retrieve these binaries from flash memory, as we did not have access to a jailbreak for iPhone 11 running iOS 13.5.1. It’s ironic that the exploit is able to plant arbitrary code on an up-to-date device and yet the owner of the phone can’t introspect their phone to see it themselves because they don’t know how to bypass the protections :/

[deleted]

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#199
post #49

Earlier quoted context omitted.

Seems fairly hypocritical in a number of ways. From our own companies actions, like Blackwater, to our allies actions, like Saudi Arabia, to our own government's actions, like "Collateral Murder" or events in Yemen. Why punish Israel?

Israeli courts rejected the case to revoke NSOs export license which would then implicate the state itself. IANAL but I think the case can be made that the export of NSOs software is against US law and a violation of the Wassenaar Arrangement. See: 5D002.C.1 So in theory if Israel is allowing one of its companies to break US law then it would make sense to use that as a basis to stop aid to Israel which may be what O…

Can you elaborate why do you think that export of NSOs software would be against US law, preferably which specific law?

My first assumption is that the act isn't covered by any US law at all. For some analogy, the murder of Jamal Khashoggi does not violate any US law as the many US laws regarding murder (i.e. the separate criminal statutes of each of the US states plus any federal laws that may apply) do not regulate acts done by Saudi citizens to Saudi citizens in Istanbul.

So the question becomes not about legality but about policy - whether the act harms US interests. And arguably selling of arms and tools by US allies (e.g. Israel) to US allies (e.g. Saudi Arabia) is not against US policy and thus there's no grounds to apply any sanctions - now, if NSO would sell the same things to Iran, that would be a different issue.

USA could have standing if NSOs tools have been used to hack journalists in USA - but this is not what this article is about. If NSOs tools have been used to hack journalists in Saudi Arabia or United Arab Emirate or Mexico, that's not a violation of USA laws; and if this has happened according to the legal permissions of the respective government (no matter how lax or arbitrary granting these legal permissions may be) then it's not a violation of any law; if we look from the purely legal perspective and not the moral one, it's perfectly legitimate for sovereign states to make laws that abuse their journalists as much as the state wants as long as it doesn't rise to the level of crimes against humanity. Almost any act or argument against a dictatorship abusing their people is inherently political, not legal.

One incident where NSO may be in hot water is the hacking of Rania Dridi described in the original article if the events happened in London (it's unclear to me from the description) - then this may be cause to assert that NSO are complicit in violating UK law (but not USA law).

Re: Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit

#200
post #85

Earlier quoted context omitted.

Google has a very good internal security research team and there hasn't been a high impact/zero click RCE on androids that Google themselves maintain for a while. Considering the recent iOS exploits, you're likely to be a little bit safer on a Google phone and common sense at the moment - but I'm 100% sure that a player like NSO will have an exploit for your phone as well. Might have more luck with a dedicated "locke…

Apple's security architecture is leagues ahead of Android's. They have bespoke innovative protections at the hardware and hypervisor level, as well as an actual security CPU (as opposed to TrustZone on Androids, which is always swiss cheese in one way or another). This is largely possible because Apple are building their own silicon (none of the other silicon vendors are anywhere near as competent in this field). I s…

Zerodium pays a little more for Android zero-click hacks, so I'm not sure about Apple being more valuable.
Post reply on HN